Skip to content

Google Chrome Zero-Day CVE-2026-11645: V8 Out-of-Bounds Write Actively Exploited Before Patch

Google has released Chrome 149.0.7762.95 patching CVE-2026-11645, an out-of-bounds write in the V8 JavaScript engine that was actively exploited before disclosure. CISA has added the flaw to the Known Exploited Vulnerabilities catalogue. All users and enterprise deployments should update immediately — CISA's federal deadline is 30 June.

Article security-operations

Google has released an emergency update for Chrome addressing CVE-2026-11645, a high-severity out-of-bounds write in the V8 JavaScript engine that was being exploited in the wild before the patch was available. This is the third Chrome zero-day confirmed exploited in 2026 and the first since April’s CVE-2026-3854 (which targeted the same V8 engine subsystem).

CISA added CVE-2026-11645 to its Known Exploited Vulnerabilities catalogue on 9 June, setting a 30 June remediation deadline for federal agencies and providing strong guidance for the broader enterprise community.

Vulnerability Details

CVE-2026-11645 is an out-of-bounds write in V8, Chrome’s JavaScript and WebAssembly engine. Out-of-bounds writes in JavaScript engines allow an attacker to corrupt adjacent memory structures — in practice, this enables arbitrary code execution within the renderer process (the sandboxed process that handles web content). Combined with a sandbox escape, this achieves full code execution on the user’s machine.

The vulnerability is triggered by visiting a specially crafted web page. No additional user interaction is required beyond opening the page. Drive-by download attacks — where a victim visits a compromised or malicious website and malware is silently installed — are the primary exploitation vector.

Google has not disclosed the full technical details of the exploitation at the time of patching, a standard practice to give time for the update to propagate. The disclosure confirms active exploitation, meaning threat actors had working exploit code before 9 June.

Affected: Chrome versions prior to 149.0.7762.95 on Windows, macOS, and Linux. Chrome-based browsers (Microsoft Edge, Brave, Opera, Samsung Internet) are also affected and will receive their own updates based on the Chromium patch.

Patched: Chrome 149.0.7762.95 and later.

Checking and Updating Chrome

Users can verify their Chrome version by navigating to chrome://settings/help. If an update is available, Chrome will download it automatically from this page.

Enterprise deployment (Chrome Browser Cloud Management or Group Policy):

  • Force update via GoogleUpdateEnabled policy and push the minimum version policy to 149.0.7762.95
  • Chrome Browser Cloud Management allows immediate fleet-wide version enforcement from the Admin Console

Microsoft Edge (also V8-based): Microsoft released Edge 149.0.2903.87 on the same day, patching the same underlying Chromium flaw. Enterprise teams managing Edge via Microsoft Intune or Group Policy should deploy the Edge update with the same urgency.

Exploitation Context

This is the ninth Chrome/Chromium V8 vulnerability exploited in the wild since 2024. V8 is one of the most complex and most targeted codebases in the browser attack surface. The combination of:

  • Ubiquitous deployment (Chrome holds approximately 65% of desktop browser market share)
  • JavaScript engine complexity making zero-days statistically inevitable
  • High value of renderer compromise as a stepping stone to endpoint compromise

…makes Chrome V8 zero-days a persistent enterprise security concern that cannot be addressed through policy alone — only through maintaining current browser versions across the enterprise fleet.

Enterprise Implications

For enterprise security teams:

Browser version currency: CVE-2026-11645 underscores why managed Chrome deployments must enforce auto-update policies. Chrome’s background update mechanism is effective for consumer devices; enterprise environments that restrict update server access or require manual approval for version changes face elevated risk from zero-day windows.

Browser isolation: Organisations deploying commercial browser isolation solutions (cloud-rendered browsing) are not affected by CVE-2026-11645 through the browser isolation path — the rendering occurs remotely. This is the primary security advantage of browser isolation for high-risk user groups.

Endpoint telemetry: Post-exploitation of a Chrome zero-day typically involves process injection from the renderer or child processes. EDR telemetry watching for unusual process spawning from chrome.exe child processes or unexpected network connections from renderer processes provides detection coverage for the post-exploitation phase.

Share this article

Related Intelligence

🛡️ SecOps

Google Patches Fourth Chrome Zero-Day of 2026 — CVE-2026-5281 Use-After-Free in WebGPU

Google has patched CVE-2026-5281, a use-after-free vulnerability in Chrome's Dawn WebGPU implementation that is being actively exploited in the wild. This is the fourth Chrome zero-day exploited in attacks in 2026. CISA added it to the KEV catalogue on 1 April with a deadline of 15 April for federal agencies. Update to Chrome 146.0.7680.177/178.

#chrome +6
🛡️ SecOps

Ivanti Sentry CVE-2026-10520: CVSS 10.0 Pre-Authentication RCE Exploited After PoC Release

Ivanti has disclosed CVE-2026-10520, a CVSS 10.0 pre-authentication remote code execution vulnerability in Ivanti Sentry (formerly MobileIron Sentry) that is being actively exploited following public proof-of-concept release. A companion OS command injection flaw CVE-2026-10523 (CVSS 9.4) affects the same platform. Both require immediate action for all organisations running Ivanti Sentry in their mobile device management infrastructure.

#ivanti +9
🛡️ SecOps

Microsoft June 2026 Patch Tuesday: 198 CVEs and Six Zero-Days Including Wormable CVSS 9.8 HTTP.sys Flaw

Microsoft's June 2026 Patch Tuesday addresses 198 vulnerabilities across Windows, Office, Azure, and server components — including three CVSS 9.8 critical remote code execution flaws and six publicly disclosed zero-days. HTTP.sys CVE-2026-47291 is wormable, requiring no authentication or user interaction against any Windows Server with IIS or HTTP API exposed.

#microsoft +9