Vulnerability intelligence
CVE-2026-11645
Google Chromium V8
Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVSS Score
8.8
High
EPSS — Exploit Probability
5.5%
Riskier than 90% of all CVEs
Exploitation
Confirmed in the wild
KEV since 2026-06-09
Remediation
Patch available
Federal deadline 2026-06-23
13 articles across 8 outlets · first covered Jun 9, 2026 · latest Jun 10, 2026
Tracked incidents
Coverage timeline
-
CISA flags Arista, Chrome, Cisco flaws; patch by June 23securityaffairs.com · Jun 10, 2026
-
Havoc Stager Uses Fake Invoices to Hit South American Firmssecurityonline.info · Jun 10, 2026
-
Architectural Exposure: Developers Extract Apple’s Subterranean Core Prompts for Siri AIsecurityonline.info · Jun 10, 2026
-
Critical Check Point VPN Flaw Under Active Attack Amid New CVEssecurityonline.info · Jun 10, 2026
-
CISA warns of critical flaws in Chromium, Arista and Cisco gearsecurityonline.info · Jun 10, 2026
-
CISA warns of actively exploited Chrome V8 flaw CVE-2026-11645www.cisa.gov · Jun 9, 2026
-
CISA warns of actively exploited Chrome V8 flaw CVE-2026-11645cisa.gov · Jun 9, 2026
-
CVE-2026-11645: Exploited Chrome V8 Bug Enables In-Browser Code Executionsocradar.io · Jun 9, 2026
-
Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Nowthehackernews.com · Jun 9, 2026
-
Google patches Chrome V8 zero day being exploited in the wildsecurityaffairs.com · Jun 9, 2026
-
Google patches Chrome following exploited CVE-2026-11645 zero daywww.infosecurity-magazine.com · Jun 9, 2026
-
Google Chrome 149 fixes critical V8 zero day flaw CVE-2026-11645www.securityweek.com · Jun 9, 2026
-
New Chrome Security Update Addresses Critical V8 Exploit in the Wildsecurityonline.info · Jun 9, 2026