Breakglass
Incidents
← IncidentsConnecting…
INC-0010·Mercy Valley Community Hospital·Staff browsersReplay of a real KEV entrySimulated hospital

Google Chromium V8 flaw on staff browsers: nothing Breakglass can safely change, so it reports and stops

CVE-2026-87491, Google Chromium V8 (CISA KEV). Nothing sits in front of this asset that Breakglass can safely change, so it reports and stops.

– ADVISORY ONLY
234688:08:29
no clock: no change made
federal due window: 14 days

fig. 1 Evidence

No edge connector in front of this asset, so there's no route to measure or protect. Breakglass reports the advisory and takes no action.

fig. 5Agent trace · local loop (Guild unavailable for this run) local-0010-74581every tool call, logged
0100:00.0triggeradvisory.insert CVE-2026-87491 entered the advisory stream (REPLAY) → session started
0200:00.1toolinventory.match browser · Google Chromium V8 141
0300:00.2stateadvisory_only Staff browsers has no edge connector; IT is told to apply the vendor's fix

fig. 0 The advisory

What the government's list says
CVE-2026-87491Replay of a real KEV entry
Google Chromium V8 Out of Bounds Write Vulnerability

Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Added to KEV
Sep 9, 2026
Federal due date
Sep 23, 2026 (14 days after listing)
EPSS
3.1% chance of exploitation in 30 days · 87.5th percentile (2026-10-04)
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Timeline

UTC
Advisory ingested
04:29:41 UTC
Trigger
Replay of a real KEV entry into the advisory stream
Agent runtime
Local loop (Guild unavailable for this run), same policy file · strategy: containment-first
Opened
04:29:41 UTC
Closed
04:29:41 UTC

Mercy Valley is a fictional hospital; its portal is a harmless twin and the "attack" traffic is a benign marker request. What's live and what's simulated.