Google Releases Patch for Chrome Vulnerability Exploited in the Wild
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-11645 | Out-of-Bounds Read/Write in Google Chrome V8 Enables In-Sandbox Code Execution CVE-2026-11645 is an out-of-bounds read and write (CWE-125/CWE-787) in V8, the JavaScript engine used by Google Chrome and Chromium. A remote attacker triggers the flaw by luring a user to a crafted HTML page, where malicious script causes V8 to read and write outside allocated memory buffers. Successful exploitation allows the attacker to execute arbitrary code inside the browser's security sandbox, providing limited privileges within that process rather than full system compromise. All Google Chrome versions prior to 149.0.7827.103 are affected, along with the Chromium V8 component identified by CISA. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-06-09, and related headlines describe an actively exploited Chrome V8 zero-day, though no public proof-of-concept is known and ransomware use is unconfirmed. Do: Update Google Chrome to 149.0.7827.103 or later and restart the browser to load the patched V8, prioritizing systems exposed to untrusted web content; because the flaw is in CISA's KEV catalog, federal agencies must apply vendor mitigations or follow BOD 22-01 guidance within the required timeframe. Organizations running Chromium-derived browsers (e.g., Edge, Brave, Opera) should apply vendor updates that incorporate the patched V8 as they become available. Restricting browsing of untrusted sites from high-value systems is a reasonable interim measure, and no public exploit code is known at this time. | 8.8 | 2% | KEV |
| massbillions of users (Chrome holds roughly two-thirds of global browser market share) |
Full article267 words · extracted from infosecurity-magazine.com · click to collapse
Google has released an emergency update to patch 74 Chrome vulnerabilities, including a high-severity flaw that has been exploited in the wild.
This is the fifth Chrome zero-day vulnerability in 2026 that has been exploited before a patch has been made available.
The security bulletin, published on June 8, include fixes for 17 critical vulnerabilities, 55 high-severity ones and tow medium-severity ones.
The security fixes will roll out “over the coming days/weeks” for Chrome users on Windows, Mac and Linux.
$55,000 For Reporting CVE-2026-11645 to Google
Among these, CVE-2026-11645 is an out of bounds read and write vulnerability affecting V8 in Google Chrome versions prior to 149.0.7827.103.
It was reported to Google on April 27 by a security researcher identified by Google as ‘303f06e3,’ who has previously reported Chrome vulnerabilities. They were awarded $55,000 for disclosing it to the Chrome security team.
When exploited, CVE-2026-11645 allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. It has been allocated a high-severity rating of 8.8.
Google confirmed it is aware of this flaw being exploited in the wild.
However, it did not provide any additional details about the exploitation evidence.
“Access to bug details and links may be kept restricted until a majority of users are updated with a fix,” the company said in the advisory.
“We will also retain restrictions if the bug exists in a third-party library that other projects similarly depend on, but haven’t yet fixed.”
Image credits: Mijansk786 / Wachiwit / Shutterstock.com
Read now: Patch Responsibility Remains Up for Grabs as AI Unearths Decades of Flaws
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/google-patch-chrome-vulnerability/