What CVE-2026-11645 Is and Why It Matters
CVE-2026-11645 is a high-severity Chrome zero-day vulnerability in the V8 JavaScript and WebAssembly engine that allows out-of-bounds memory access, enabling attackers to corrupt memory and run arbitrary code inside the browser’s sandbox through a crafted HTML page, and it is already being exploited in the wild. Classified with a CVSS score of 8.8, this V8 engine security flaw affects Chrome versions prior to 149.0.7827.103. Because it involves memory corruption, successful attacks can lead to code execution within the sandbox, potentially becoming a stepping stone to broader compromise when chained with other bugs. Google has confirmed that an exploit for CVE-2026-11645 exists, but it is withholding technical details until most users install the browser security update. The vulnerability has also been added to CISA’s Known Exploited Vulnerabilities catalog, confirming verified, active use by threat actors.
How the V8 Out-of-Bounds Flaw Can Be Exploited
The CVE-2026-11645 patch fixes an out-of-bounds read and write condition in Chrome’s V8 engine. In practical terms, a malicious website can abuse this bug to read or write data outside the intended memory region, which can break normal browser behavior and give the attacker precise control over code execution within the sandbox. According to the National Vulnerability Database, “Out-of-bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.” The attack surface is any user who visits a harmful page in an outdated Chrome or Chromium-based browser. While the sandbox limits direct access to the underlying system, attackers often chain such flaws with other vulnerabilities to escape the sandbox or steal sensitive data processed inside the browser.
Google’s Security Update: 74 Fixes and a Critical Zero-Day
Google’s latest Chrome release delivers security updates for 74 distinct vulnerabilities, and the CVE-2026-11645 zero-day stands out as one of the most critical issues addressed. The company credits security researcher “303f06e3” with discovering and responsibly reporting the flaw on April 27, 2026, and has awarded a bug bounty of USD 55,000 (approx. RM253,000) for the finding. With this release, Google has now fixed five actively exploited Chrome zero-day vulnerabilities this year, including CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, and CVE-2026-5281. This pattern underlines how browsers remain prime targets for attackers, who focus on engine-level issues like V8 memory corruption bugs. While Google has confirmed the existence of an exploit in the wild for CVE-2026-11645, it has intentionally withheld exploitation details until a large portion of the user base installs the update.
CISA’s KEV Catalog and the Wider Risk Landscape
CISA has added CVE-2026-11645 to its Known Exploited Vulnerabilities (KEV) catalog alongside flaws affecting Cisco Catalyst SD-WAN Manager and Arista EOS, highlighting that the Chrome V8 issue is part of a broader active threat environment. The KEV listing signals confirmed, real-world exploitation rather than theoretical risk, and it also drives mandatory remediation timelines for certain organizations. Federal civilian agencies have been ordered to apply fixes or mitigations for the three newly listed vulnerabilities by June 23, 2026, underscoring the urgency. For enterprises, inclusion in the KEV catalog should elevate CVE-2026-11645 to a top-priority browser security update item. Because browser sessions often touch email, collaboration tools, and internal dashboards, a successful memory corruption attack can give adversaries a powerful foothold in corporate environments, even if the initial code execution remains inside the sandbox.

How to Patch Chrome and Other Chromium-Based Browsers Now
To protect against this Chrome zero-day vulnerability, users should install the CVE-2026-11645 patch immediately by updating to Chrome version 149.0.7827.102 or 149.0.7827.103 on Windows and macOS, and 149.0.7827.102 on Linux. You can trigger the update by going to More > Help > About Google Chrome and then selecting Relaunch after the update downloads. This ensures the V8 engine security flaw is fixed and the new protections are active. Users of other Chromium-based browsers—including Microsoft Edge, Brave, Opera, and Vivaldi—should also apply their respective browser security updates as soon as they are released, since they share much of the same underlying engine code. For organizations, updating managed browsers, enforcing automatic updates, and monitoring KEV-listed vulnerabilities should be treated as standard operational security practice, given this is already the fifth exploited Chrome zero-day this year.






