High severity8.8CISA KEVNVD Advisory· Published Jun 9, 2026· Updated Jun 9, 2026
CVE-2026-11645
CVE-2026-11645
Description
Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- osv-coords4 versionspkg:apk/chainguard/chromiumpkg:apk/wolfi/chromiumpkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/chromium&distro=openSUSE%20Tumbleweed
< 149.0.7827.102-r0+ 3 more
- (no CPE)range: < 149.0.7827.102-r0
- (no CPE)range: < 149.0.7827.102-r0
- (no CPE)range: < 149.0.7827.102-bp160.1.1
- (no CPE)range: < 149.0.7827.102-1.1
Patches
Vulnerability mechanics
References
3- chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.htmlnvdRelease NotesVendor Advisory
- issues.chromium.org/issues/506689381nvdPermissions Required
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
15- ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and MoreThe Hacker News · Jun 15, 2026
- Week in review: Exploited Check Point VPN zero-day, Oracle PeopleSoft servers under attackHelp Net Security · Jun 14, 2026
- CISA Warns of Google Chromium 0-Day Vulnerability Exploited in AttacksCyber Security News · Jun 10, 2026
- CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active ExploitationThe Hacker News · Jun 10, 2026
- No Patch Planned for Exploited Arista EOS VulnerabilitySecurityWeek · Jun 10, 2026
- Google Chrome 0-Day Vulnerability Exploited in the Wild — Update NowCyber Security News · Jun 9, 2026
- Chrome's zero-day Whac-A-Mole continues with fifth exploited bug of the yearThe Register Security · Jun 9, 2026
- Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch NowThe Hacker News · Jun 9, 2026
- Google patches Chrome zero-day exploited in the wild (CVE-2026-11645)Help Net Security · Jun 9, 2026
- Update Chrome: Google patches actively exploited vulnerability and 73 othersMalwarebytes Labs · Jun 9, 2026
- Google Releases Patch for Chrome Vulnerability Exploited in the WildInfosecurity Magazine · Jun 9, 2026
- Google patches new Chrome zero-day flaw exploited in the wildBleepingComputer · Jun 9, 2026
- Google Patches 5th Chrome Zero-Day Exploited in 2026SecurityWeek · Jun 9, 2026
- Google CVE-2026-11645 Added to CISA KEV Under Active ExploitationVypr Intelligence · Jun 9, 2026
- CISA Adds Three Known Exploited Vulnerabilities to CatalogCISA Alerts