Vulnerability intelligence
CVE-2026-11645
Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
Google Chromium V8
Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVSS Score
8.8
High
EPSS — Exploit Probability
2.2%
Riskier than 81% of all CVEs · checked 2026-09-07
Exploitation
Confirmed in the wild
KEV since 2026-06-09
Remediation
Patch available
Federal deadline 2026-06-23
CISA required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Deadline for federal agencies: 2026-06-23.
18 articles across 9 outlets · first covered Jun 9, 2026 · latest Sep 9, 2026
Coverage timeline
-
Chrome Patches Exploited V8 Zero Day Allowing Code Executionthehackernews.com · Sep 9, 2026
-
CISA Flags Actively Exploited Chrome Flaw as Sixth 2026 Zero-Daysecurityaffairs.com · Sep 4, 2026
-
Google Patches Actively Exploited Chrome V8 Zero Daysecurityaffairs.com · Sep 4, 2026
-
Google Patches Chrome Zero Day Exploited in V8 Attacksthehackernews.com · Sep 4, 2026
-
CISA flags Arista, Chrome, Cisco flaws; patch by June 23securityaffairs.com · Jun 10, 2026
-
Havoc Stager Uses Fake Invoices to Hit South American Firmssecurityonline.info · Jun 10, 2026
-
Architectural Exposure: Developers Extract Apple’s Subterranean Core Prompts for Siri AIsecurityonline.info · Jun 10, 2026
-
Critical Check Point VPN Flaw Under Active Attack Amid New CVEssecurityonline.info · Jun 10, 2026
-
CISA warns of critical flaws in Chromium, Arista and Cisco gearsecurityonline.info · Jun 10, 2026
-
CISA warns of actively exploited Chrome V8 flaw CVE-2026-11645www.cisa.gov · Jun 9, 2026
-
CISA warns of actively exploited Chrome V8 flaw CVE-2026-11645cisa.gov · Jun 9, 2026
-
CVE-2026-11645: Exploited Chrome V8 Bug Enables In-Browser Code Executionsocradar.io · Jun 9, 2026
-
Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Nowthehackernews.com · Jun 9, 2026
-
Google patches Chrome V8 zero day being exploited in the wildsecurityaffairs.com · Jun 9, 2026
-
Google patches Chrome V8 flaw CVE-2026-11645 amid 74 fix updatewww.malwarebytes.com · Jun 9, 2026
-
Google patches Chrome following exploited CVE-2026-11645 zero daywww.infosecurity-magazine.com · Jun 9, 2026
-
Google Chrome 149 fixes critical V8 zero day flaw CVE-2026-11645www.securityweek.com · Jun 9, 2026
-
New Chrome Security Update Addresses Critical V8 Exploit in the Wildsecurityonline.info · Jun 9, 2026