Junglewise Threat Intelligence

CVE-2026-11645: Google Chrome V8 out of bounds read and write

CVE-2026-11645 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2026-06-09

Technologies: Google Chromium V8, Google Chrome, Microsoft Edge, Opera Software Opera. Vendors: Google, Microsoft, Opera Software.

Executive brief

A critical vulnerability has been identified in the V8 engine used by Google Chrome and other Chromium-based browsers like Microsoft Edge and Opera. By tricking a user into visiting a specially crafted website, an attacker can execute malicious code within the browser's security sandbox. This could lead to browser crashes, unauthorized access to sensitive information within the browser session, or serve as a stepping stone for further attacks on the user's computer.

Technical details

An out-of-bounds (OOB) read and write vulnerability exists in the V8 JavaScript and WebAssembly engine within Google Chromium. The flaw is triggered when the engine improperly handles memory access during the processing of JavaScript content, which can be exploited by a remote attacker via a crafted HTML page. Successful exploitation allows for arbitrary code execution (ACE) within the confines of the browser's sandbox. This vulnerability has been reported as being exploited in the wild. Users should update to Google Chrome version 149.0.7827.103 or later, or the equivalent version for other Chromium-based browsers.

Affected products

  • Google Chrome prior to 149.0.7827.103
  • Microsoft Edge
  • Opera Software Opera

Timeline

  • 2026-06-08: disclosed
  • 2026-06-09: advisory
  • 2026-06-09: patched: Fixed in Chrome version 149.0.7827.103
  • 2026-06-09: exploited: Reported as exploited in the wild at time of publication.

Related threats