Chrome V8 zero-day actively exploited, patch now
Google patched CVE-2026-87491, an actively exploited V8 zero-day allowing code execution in Chrome's renderer sandbox. Chrome 153.0.8010.36 fixes the out-of-bounds write flaw reported August 6. This is the seventh Chrome zero-day exploited in 2026. All Chromium-based browsers require updates.
Meanwhile, Spanner dropped per-transaction mutation limits, and Btrfs Zstd decompression got 7.8% faster in Linux 7.4.
In this issue:
- Chrome 153.0.8010.36: CVE-2026-87491 V8 out-of-bounds write patch
- Google Spanner: per-transaction DML mutation limits removed, 80K cap per statement
- Linux 7.4 Btrfs: Zstd decompression 7.8% faster via direct page writes
- Cloudflare Workers: Node.js-compatible module registry, 64 MiB bundle limit
Chrome V8 Zero-Day Exploited in the Wild — Patch Now
The Signal
Google patched CVE-2026-87491, an out-of-bounds write in V8 actively exploited to execute code inside Chrome's sandbox.
What Changed
- Chrome 153.0.8010.36 patches the V8 out-of-bounds write flaw reported August 6
- Exploit allows remote code execution via crafted HTML inside Chrome's renderer sandbox
- This is the seventh actively exploited Chrome zero-day in 2026
- Google released fixes for 230 total vulnerabilities in this update
- Chromium-based browsers (Edge, Brave, Opera, Vivaldi) also affected, patches pending
Operational Impact
Update immediately to Chrome 153.0.8010.36 or later. V8 vulnerabilities allow attackers to compromise renderer processes through malicious web content. While sandbox-contained, this enables further exploitation chains targeting sandbox escapes. Organizations using Chromium-embedded frameworks or Electron apps should monitor vendor patch timelines. The seventh Chrome zero-day this year indicates sustained attacker interest in browser exploitation.
Watch For
Google has not disclosed attack details or threat actor attribution. Monitor for patches to Chromium-based browsers and embedded frameworks over the next week.
Google Spanner Removes Per-Transaction DML Mutation Limits
The Signal
Google Spanner now allows unlimited DML statements per transaction, capping each statement at 80,000 mutation mods.
What Changed
- Mutation mod limit moved from transaction-level to per-DML-statement basis.
- Single transaction can contain any number of INSERT/UPDATE/DELETE statements.
- Mutation mods count rows × columns modified plus secondary index updates.
- Mutation API still enforces 80K limit at commit call, not per statement. https://cloud.google.com/blog/products/databases/spanner-removes-dml-mutation-limits
- Monitor via `mutation_count` field in `CommitStats` for entire transaction.
Operational Impact
Teams no longer need to split logical operations across multiple transactions to stay under the 80K ceiling. Applications can group DML statements by business logic rather than mutation budget. Larger transactions hold locks longer, increasing abort risk from contention. Teams using the Mutation API (`insert()`, `update()`) instead of DML still face the 80K limit per commit call.
Watch For
Monitor transaction abort rates if you consolidate previously split operations. Statements exceeding 80K mods individually still fail; consider Partitioned DML for bulk updates.
Btrfs Zstd Decompression Gets 7.8% Faster in Linux 7.4
The Signal
Btrfs Zstd decompression in Linux 7.4 eliminates double-write overhead for sequential read speedups up to 7.8%.
What Changed
- Patch queued for Linux 7.4 removes intermediate scratch buffer in Btrfs Zstd decompression path.
- Old code wrote every byte twice: once to scratch buffer, then copied to page cache.
- New `zstd_map_dest()` uses `kmap` to write decompressed data directly to destination pages.
- Sequential reads improve 7.8% (4K sectors), 3.6% (16K), 6.8% (64K); random 4K reads ~3% faster.
- https://www.phoronix.com/news/Btrfs-Zstd-Faster-Decompress
Operational Impact
All Btrfs filesystems using Zstd compression will see faster reads with no configuration changes. Systems running compressed root filesystems or database workloads on Btrfs benefit most from reduced read latency. The optimization applies only to decompression; write paths are unchanged.
Watch For
Separate in-kernel Zstd improvements are pending for Linux 7.4. Combined gains may exceed these numbers.
Cloudflare Workers Rewrites Module Registry for Node.js Compatibility
The Signal
Cloudflare rebuilt the workerd module registry to match Node.js resolution semantics and raised bundle limits to 64 MiB.
What Changed
- Enable via `new_module_registry` compatibility flag in wrangler.toml or worker config.
- Module specifiers now resolve as URLs, not filesystem paths; query strings create distinct instances.
- `import.meta.resolve()`, `import.meta.url`, and `import.meta.main` now work per ECMAScript spec.
- `require(esm)` follows Node.js rules: returns namespace or `module.exports` named export when present.
- Import attributes (e.g., `with { type: 'json' }`) are validated; unknown types throw TypeError.
- WebAssembly modules support source phase imports (`import source wasmModule from './add.wasm'`).
- Bundle size limit raised to 64 MiB uncompressed across all plans; compressed limit removed.
Operational Impact
Teams porting Node.js applications can now deploy less-transformed code; bundlers like Rolldown or Vite can rely on runtime module resolution instead of inlining everything. Modules with top-level `await` cannot be required (throws synchronously), matching Node.js `ERR_REQUIRE_ASYNC_MODULE` behavior. The flag is opt-in with no automatic rollout date—you must explicitly enable and test it.
Watch For
No default-on compatibility date set yet. Test your module graph with the flag enabled; error messages and module identity rules changed from the original registry.
Quick Reads
- Chrome V8 — Zero-day vulnerability actively exploited; update to Chrome 153.0.8010.36 immediately.
- Google Spanner — Removes per-transaction mutation limits; now allows unlimited DML statements per transaction.
- Linux 7.4 Btrfs — Zstd decompression gains up to 7.8% speed improvement on sequential reads.
- Cloudflare Workers — New module registry matches Node.js resolution; bundle limit raised to 64 MiB.
Subscribe to Signal Field
Data & infrastructure news. Subscribers get new posts by email a day before they go live on the site.
Email signup is coming soon — in the meantime, follow the Signal Field RSS feed.