securityaffairs.com 6/9/2026, 11:30:29 AM · external

Google patches Chrome V8 zero day being exploited in the wild

Google patches Chrome V8 zero day being exploited in the wild
CyberSIXT Evidence Panel
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

GOOGLE has released emergency updates for a new Chrome zero-day vulnerability identified as CVE-2026-11645, affecting the V8 JavaScript engine. This flaw, the fifth actively exploited zero-day in 2026, allows for out-of-bounds memory access, potentially leading to denial of service, privilege escalation, or remote code execution. Google confirmed that an exploit for this vulnerability is already in the wild and has not disclosed technical details. This year's previous zero-day vulnerabilities include issues related to CSS, graphics libraries, and the WebGPU component.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline