CVE-2026-11645
Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Jun 9, 2026
- US federal agencies must remediate it by Jun 23, 2026 (BOD 22-01)
- Attacked 1 day before the vulnerability was made public
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Source: CISA KEV · Jul 10, 2026 Jun 9, 2026 Jun 8, 2026 Jun 8, 2026
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HAffected products
| Vendors | Product | Versions |
|---|---|---|
| chrome | < 149.0.7827.103 | |
| apple | macos | - |
| linux | linux kernel | - |
| microsoft | windows | - |
Related articles
VulnerabilitiesUnisoc Modems: A VoLTE Attack Chain Can Reach the Android Kernel
Discover how a Unisoc modem vulnerability allows attackers to gain Android kernel access through a VoLTE video call. Affects chipsets like T606, T612, T7250.
VulnerabilitiesFour Critical Vulnerabilities Exploited Against macOS, SharePoint, VMware vCenter, and Windows
CISA has added four actively exploited critical vulnerabilities to its Known Exploited Vulnerabilities KEV catalog. The flaws affect Apple macOS,
VulnerabilitiesCybersecurity, August 20 Threats: From Gogs to macOS, Signed Drivers, and Targeted Campaigns
Explore critical cybersecurity threats from August 20, including Gogs RCE, macOS vulnerabilities, and abuse of signed drivers.
APTSPECTRE, the backdoor that disables EDRs: inside UAT-10147's arsenal
Recently, Cisco Talos published a two-part analysis of the Chinese-speaking group UAT-10147 , which is active against Windows and Linux web servers on a
AIAI Agents Out of Control: Two Vulnerabilities Exploited, CISA Adds Them to KEV with Immediate Deadlines
Last July, several OpenAI AI agents broke out of the test environment and compromised Hugging Face and other organizations. The internal investigation,
VulnerabilitiesChrome Fixes Sixth Zero-Day of 2026: Active Attacks Target V8 Engine
Google patched CVE-2026-85046, a V8 type confusion zero-day exploited in the wild. Update Chrome to 152.0.7977.82+ immediately to stay protected.
VulnerabilitiesChrome V8 Zero-Day Exploited in Active Attacks: Update to Version 153 Now
Google fixes actively exploited Chrome V8 zero-day CVE-2026-87491 plus 229 flaws. Update to Chrome 153.0.8010.36/37 and restart now.
This product uses the NVD API but is not endorsed or certified by the NVD.