Google ships emergency Chrome update for actively exploited V8 flaw CVE-2026-11645
Chrome users should update now. Google shipped an emergency fix June 9 for CVE-2026-11645, a high-severity V8 engine flaw already exploited in the wild to run code via a malicious webpage. It is the fifth actively exploited Chrome zero-day patched in 2026. $GOOGL
Anyone who uses Google Chrome should update the browser today. On June 9, 2026, Google released an emergency security update to patch CVE-2026-11645, a high-severity vulnerability in V8, the JavaScript engine that powers Chrome. According to Help Net Security and The Hacker News, the flaw is an out-of-bounds read and write issue that lets a remote attacker run code inside the browser after a victim loads a crafted webpage, and Google has confirmed it is already being exploited in the wild. The fix ships in Chrome version 149.0.7827.102, with builds for Windows, macOS and Linux, and is rolling out to users over the coming days. This is the fifth actively exploited Chrome zero-day Google has patched in 2026, part of an update that closed 72 security issues in total, 17 of them rated critical. Because the exploit only requires a user to visit a malicious page, waiting for the automatic rollout leaves a window of exposure. Users can force the update through the About Google Chrome menu and then restart the browser to apply it. $GOOGL