Google confirms hackers are exploiting a new Chrome zero-day in the V8 engine, urges all users to update
Google has confirmed that attackers are actively exploiting a newly discovered flaw in Chrome's V8 engine. A booby-trapped web page can let an attacker run code inside the browser's sandbox. It is the fifth Chrome zero-day exploited in the wild this year, and Google has released fixed stable builds for Windows, Mac and Linux.
Google Chrome V8 zero-day actively exploited (CVE-2026-11645). Out-of-bounds memory access, rated high severity. A malicious web page can execute code inside Chrome's sandbox and be chained to bypass memory protections. Fifth Chrome zero-day of 2026. Fixed stable builds released June 8 for Windows, Mac and Linux. Update and fully restart the browser to apply.
Published on
TikTokFacebookYouTubeBlueskyX