Back to News
Vulnerabilities

Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now

Cyber RTJune 9, 20263 min read
Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now

Google has issued security updates for 74 vulnerabilities, including the actively exploited CVE-2026-11645, a high-severity flaw in Chrome's V8 engine. Discovered by researcher "303f06e3," this out-of-bounds memory access allows remote code execution. Users should update Chrome to versions 149.0.7827.102/.103 for Windows and macOS, and 149.0.7827.102 for Linux. Other Chromium-based browser users should also apply updates when available.

Google has recently rolled out security updates to patch 74 vulnerabilities in its Chrome browser, one of which is actively being exploited. The vulnerability, identified as CVE-2026-11645, holds a high-severity rating with a CVSS score of 8.8. It is characterized as an out-of-bounds memory access issue within V8, the JavaScript and WebAssembly engine used by Chrome. The flaw allows a remote attacker to execute arbitrary code within a sandbox environment by using a specially crafted HTML page. This vulnerability was documented in the National Vulnerability Database (NVD), highlighting its potential impact on users who have not yet updated their browsers to the latest version. A security researcher known by the pseudonym "303f06e3" discovered and reported the vulnerability on April 27, 2026. In recognition of their responsible disclosure, Google awarded the researcher a bug bounty of $55,000. This reward underscores the importance Google places on collaboration with the security community to identify and mitigate potential threats. Google has confirmed that an exploit for CVE-2026-11645 is present in the wild, though they have withheld detailed information about the exploit. This decision aims to protect users by ensuring that the majority have updated their systems before more specifics are released, thereby minimizing the risk of further exploitation. This update marks the fifth actively exploited Chrome zero-day vulnerability that Google has addressed this year. Other vulnerabilities patched include CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, and CVE-2026-5281, reflecting a continued effort to enhance browser security amidst ongoing threats. To safeguard against these vulnerabilities, users are urged to update their Chrome browsers to the latest versions: 149.0.7827.102/.103 for Windows and macOS, and 149.0.7827.102 for Linux. Users can verify their update status by navigating to More > Help > About Google Chrome and selecting Relaunch to ensure the latest patches are applied. Additionally, users of other browsers built on the Chromium engine, such as Microsoft Edge, Brave, Opera, and Vivaldi, are advised to apply similar updates as they become available. This proactive approach is essential for maintaining security across different platforms and preventing potential exploits. For those interested in staying informed about security updates and other tech news, the article encourages following their content on platforms like Google News, Twitter, and LinkedIn for exclusive updates and insights.