Chrome V8 JavaScript engine out-of-bounds read/write zero-day exploited in the wild (CVE-2026-11645)
Vulnerability
Summary
Hide ▲
Show ▼
Google has patched CVE-2026-11645, a Chrome V8 JavaScript engine zero-day that was exploited in the wild and could let remote attackers run code inside the browser sandbox. The flaw was triggered with crafted HTML pages, putting Chrome users on Windows, Mac, and Linux at risk until the emergency update reached their devices. Google said the fix was rolling out through Stable Desktop builds worldwide.
Related Happenings
Google Dialogflow CX Code Blocks shared-runtime isolation security flaw
Vulnerability
H score32
First: 07.07.2026 19:37
Last: 07.07.2026 19:37
Sources 1
About this happening:
Google Dialogflow CX Code Blocks had a shared-runtime isolation flaw that could let one editable agent affect other Code Block-enabled agents in the same Google Cloud pr...
Google Dialogflow CX Code Blocks shared-runtime isolation security flaw
VulnerabilityAbout this happening: Google Dialogflow CX Code Blocks had a shared-runtime isolation flaw that could let one editable agent affect other Code Block-enabled agents in the same Google Cloud pr...
Chromium JavaScript background RCE flaw
Vulnerability
H score16
First: 21.05.2026 21:13
Last: 21.05.2026 21:13
Sources 1
About this happening:
The unfixed Chromium flaw keeps JavaScript running after the browser is closed, creating remote code execution risk across Chromium-based browsers. A malicious sit...
Chromium JavaScript background RCE flaw
VulnerabilityAbout this happening: The unfixed Chromium flaw keeps JavaScript running after the browser is closed, creating remote code execution risk across Chromium-based browsers. A malicious sit...
Chrome/Dawn actively exploited use-after-free flaw (CVE-2026-5281)
Vulnerability
H score1
First: 01.04.2026 13:25
Last: 01.04.2026 13:25
Sources 1
About this happening:
Google Chrome Stable Desktop on Windows, macOS, and Linux is getting an emergency fix for CVE-2026-5281, a use-after-free flaw in Dawn/WebGPU. Google says...
Chrome/Dawn actively exploited use-after-free flaw (CVE-2026-5281)
VulnerabilityAbout this happening: Google Chrome Stable Desktop on Windows, macOS, and Linux is getting an emergency fix for CVE-2026-5281, a use-after-free flaw in Dawn/WebGPU. Google says...
Chrome Skia and V8 exploited zero-days (multiple vulnerabilities)
Vulnerability
H score31
First: 13.03.2026 11:17
Last: 13.03.2026 11:17
Sources 1
About this happening:
Chrome on Windows, macOS, and Linux is affected by two high-severity zero-days, CVE-2026-3909 and CVE-2026-3910, that Google says were exploited in the wild*...
Chrome Skia and V8 exploited zero-days (multiple vulnerabilities)
VulnerabilityAbout this happening: Chrome on Windows, macOS, and Linux is affected by two high-severity zero-days, CVE-2026-3909 and CVE-2026-3910, that Google says were exploited in the wild*...
QuickLens - Search Screen with Google Lens hit by network compromise
Incident
H score57
First: 28.02.2026 21:18
Last: 28.02.2026 21:18
Sources 1
About this happening:
The QuickLens - Search Screen with Google Lens Chrome extension was compromised and used to push malware to about 7,000 users, creating risk of credential theft*...
QuickLens - Search Screen with Google Lens hit by network compromise
IncidentAbout this happening: The QuickLens - Search Screen with Google Lens Chrome extension was compromised and used to push malware to about 7,000 users, creating risk of credential theft*...
Timeline
-
09.06.2026 09:56 4 articles · 1mo ago
Google rolls out emergency Chrome updates for CVE-2026-11645
Mitigation Patch UpdateGoogle said an exploit for CVE-2026-11645 exists in the wild and released emergency Chrome Stable Desktop updates worldwide for Windows 149.0.7827.102, Mac 149.0.7827.103, and Linux 149.0.7827.102 after an anonymous security researcher reported the zero-day two weeks earlier. The flaw is an out-of-bounds read and write in the Chrome V8 JavaScript engine that remote attackers can trigger with crafted HTML pages to execute arbitrary code inside the browser sandbox, expose memory beyond the buffer, trigger a crash, and potentially bypass ASLR.
Show sources
- Google patches new Chrome zero-day flaw exploited in the wild — www.bleepingcomputer.com — 09.06.2026 09:56
- Google patches new Chrome zero-day flaw exploited in the wild — www.bleepingcomputer.com — 09.06.2026 09:56
- Google Releases Patch for Chrome Vulnerability Exploited in the Wild — www.infosecurity-magazine.com — 09.06.2026 13:15
- Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now — thehackernews.com — 09.06.2026 14:58