Description
Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
In plain language
AI Act nowCVE-2026-11645 is a serious Chrome browser bug that lets attackers run code after you simply visit a specially crafted web page; if you haven’t updated Chrome to 149.0.7827.103 or newer, this is something a typical small business should treat as urgent.
CVE-2026-11645 is an out-of-bounds read/write in the V8 JavaScript engine in Google Chrome (pre-149.0.7827.103) that enables a remote attacker to achieve arbitrary code execution inside Chrome’s sandbox via a crafted HTML page; it is listed in CISA KEV with real-world exploitation reported.
What to do now
- Check your Chrome version on each affected computer (Chrome → Help → About Google Chrome) and note any versions earlier than 149.0.7827.103.
- Update Google Chrome to 149.0.7827.103 (or later) on every device used for web browsing.
- If you can’t update immediately, restrict web browsing to a controlled allowlist (or use a managed browser environment) and block access to untrusted websites until updates are applied.
- After updating, verify the version number again and ask IT to review browser crash/error spikes and suspicious activity around the time of browsing by staff.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
- В браузере Chrome исправили шестую 0-day-уязвимость в этом годуru-ru·Хакер (xakep.ru)·
- Google patches actively exploited Chrome zero-day (CVE-2026-85046)en-us·Help Net Security· Exploited Chrome zero-day
- Google warns of new Chrome zero-day flaw exploited in attacksen-us·BleepingComputer· Exploited Chrome zero-day
- Google Patches 6th Chrome Zero-Day of 2026en-us·SecurityWeek· Exploited Chrome zero-day
- Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Dayen·The Hacker News· Exploited Chrome zero-day
- ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and Moreen·The Hacker News· Exploited Chrome (V8) UNC6240 (ShinyHunters)
- Weekly Threat Intelligence: June 8 to June 14, 2026en-us·Daily CyberSecurity (securityonline.info)· Exploited Ivanti Sentry rce
- В Chrome исправили уязвимость нулевого дняru-ru·Хакер (xakep.ru)· Exploited Google Chrome (V8 engine) zero-day
- CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitationen·The Hacker News· Exploited Cisco Catalyst SD-WAN Manager patch-tuesday
- No Patch Planned for Exploited Arista EOS Vulnerabilityen-us·SecurityWeek· Exploited Arista EOS zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-11645 and every CVE in our database. Create a free account — no credit card required.
Create Free Account