GOOGLE has released emergency updates for a new Chrome zero-day vulnerability identified as CVE-2026-11645, affecting the V8 JavaScript engine. This flaw, the fifth actively exploited zero-day in 2026, allows for out-of-bounds memory access, potentially leading to denial of service, privilege escalation, or remote code execution. Google confirmed that an exploit for this vulnerability is already in the wild and has not disclosed technical details. This year's previous zero-day vulnerabilities include issues related to CSS, graphics libraries, and the WebGPU component.
Google patches Chrome V8 zero day being exploited in the wild
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
CISA Flags Actively Exploited Chrome Flaw as Sixth 2026 Zero-Day
securityaffairs.com
-
Google Patches Actively Exploited Chrome V8 Zero Day
securityaffairs.com
-
Google Patches Chrome Zero Day Exploited in V8 Attacks
thehackernews.com
-
Google patches Chrome V8 zero day being exploited in the wild
securityaffairs.com