AI Stories on SHORT INFO are generated & curated with AI
unverified 27 Jun, 06:09

Google confirms Chrome V8 zero-day CVE-2026-11645 exploited in the wild, fifth of 2026

Anyone on an outdated Chrome is exposed to a bug attackers are already using. Google $GOOGL confirmed CVE-2026-11645, a high-severity flaw in Chrome's V8 engine, is exploited in the wild. It is the fifth Chrome zero-day patched in 2026. Update to 149.0.7827.103. (Per The Hacker N

If you use Chrome and have not restarted it in a while, you may be running a version with a hole that attackers are already exploiting. Google $GOOGL has confirmed that CVE-2026-11645, a high-severity vulnerability rated 8.8, is being exploited in the wild. The flaw is an out-of-bounds memory access in V8, the JavaScript and WebAssembly engine that powers Chrome and other browsers built on Chromium. According to security researchers, a specially crafted web page is enough to trigger it. Successful exploitation corrupts memory inside the browser, lets an attacker run code within Chrome's sandbox, and can help bypass protections such as address space layout randomization, making further attacks easier. This is the fifth Chrome zero-day that Google has patched in 2026, following four earlier cases. The vulnerability was reported in late April by a researcher credited as 303f06e3, who received a 55,000 dollar bug bounty for responsible disclosure. Google has shipped the fix in Chrome version 149.0.7827.102 and .103 for Windows and macOS, and .102 for Linux. The practical step is simple: open Chrome's menu, check for an update, and restart the browser so the patch takes effect. Because the V8 engine is shared by other Chromium-based browsers such as Edge, Brave and Opera, users of those should watch for their own updates. (Reporting per The Hacker News and Help Net Security.)

Published on
XThreadsFacebookInstagramBluesky