← IncidentsConnecting…
INC-0010·Mercy Valley Community Hospital·Staff browsersReplay of a real KEV entrySimulated hospital
Google Chromium V8 flaw on staff browsers: nothing Breakglass can safely change, so it reports and stops
CVE-2026-87491, Google Chromium V8 (CISA KEV). Nothing sits in front of this asset that Breakglass can safely change, so it reports and stops.
– ADVISORY ONLY
234688:08:29
no clock: no change made
federal due window: 14 days
fig. 1 Evidence
No edge connector in front of this asset, so there's no route to measure or protect. Breakglass reports the advisory and takes no action.
0100:00.0triggeradvisory.insert CVE-2026-87491 entered the advisory stream (REPLAY) → session started
0200:00.1toolinventory.match browser · Google Chromium V8 141
0300:00.2stateadvisory_only Staff browsers has no edge connector; IT is told to apply the vendor's fix
fig. 0 The advisory
What the government's list saysCVE-2026-87491Replay of a real KEV entry
Google Chromium V8 Out of Bounds Write Vulnerability
Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
- Added to KEV
- Sep 9, 2026
- Federal due date
- Sep 23, 2026 (14 days after listing)
- EPSS
- 3.1% chance of exploitation in 30 days · 87.5th percentile (2026-10-04)
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Timeline
UTC- Advisory ingested
- 04:29:41 UTC
- Trigger
- Replay of a real KEV entry into the advisory stream
- Agent runtime
- Local loop (Guild unavailable for this run), same policy file · strategy: containment-first
- Opened
- 04:29:41 UTC
- Closed
- 04:29:41 UTC
Mercy Valley is a fictional hospital; its portal is a harmless twin and the "attack" traffic is a benign marker request. What's live and what's simulated.