YFarmX logoYFarmX

Tools AI-Found Vulnerability Register aifv-0047

Register entry

Chrome V8 out-of-bounds write exploited in the wild, found by a human researcher and paid $2,500 (the control row)

CVE
CVE-2026-87491
Project
Google Chrome
Component
V8
Finder
Jihyeon Jeong (human researcher)
Autonomy
human
Evidence tier
CNA credits the finder in its own advisory
Assigner
Chrome
Severity
Medium (Chromium severity)
Bounty
Paid, $2,500 (Chrome VRP)
Confidence
CONFIRMED

What happened

Fixed in Chrome 153.0.8010.36 on 8 September 2026 and exploited in the wild by a third party. The row sits in the register as a control: headlines conflated it with an AI-derived exploit chain built on 3 September, and the release note credits a person, with a $2,500 reward.

Credit as recorded: [$2,500][ 543557673 ] Medium CVE-2026-87491: Out of bounds write in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-08-06. Date basis: release note.

Sources

One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026