Google ships emergency Chrome fix for actively exploited V8 zero-day CVE-2026-11645
If you run Chrome, you are exposed until you relaunch it. Google $GOOGL pushed an emergency fix for CVE-2026-11645, an actively exploited flaw in the V8 engine that lets a booby-trapped web page run code inside the browser. It is the fifth Chrome zero-day exploited this year. Upd
Anyone who uses Google Chrome should restart the browser today. Google $GOOGL has released an emergency security update for CVE-2026-11645, a high-severity vulnerability in V8, the JavaScript and WebAssembly engine that powers Chrome. The company confirmed that a working exploit already exists in the wild, which is why the patch went out ahead of the normal schedule. The flaw is an out-of-bounds memory access, rated 8.8 on the CVSS scale. According to Google's advisory, a specially crafted web page is enough to trigger it, after which an attacker can execute code inside the browser. Out-of-bounds bugs like this can also weaken protections such as address space layout randomization, which makes chaining a second exploit easier. This is the fifth Chrome zero-day to be exploited in attacks during 2026. The patched Stable build is rolling out as 149.0.7827.102 for Windows, Mac and Linux. Updates usually install automatically, but only take effect after Chrome is fully closed and reopened, so a tab left running for days stays vulnerable. The researcher credited with the report disclosed it in late April and received a bug bounty for the work. The fix is simple to apply: open the Chrome menu, check for an update, and relaunch. Browsers built on the same Chromium core, such as Edge and Brave, typically inherit the same fix once their vendors ship it.