Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2341 articles · 161210 vulns · 36/41 feeds (7d)
← Back to list
8.8
CVE-2026-11645EXPLOITEDPATCHED
google · chrome

CVE-2026-11645: Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitra

Description

Out of bounds read and write vulnerability affecting V8 in Google Chrome versions prior to 149.0.7827.103, reported on April 27 by a security researcher, allowing a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

Affected Products

VendorProductVersions
googlechrome149.0.7827.103, 149.0.7827.102

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
googlechromecert_advisory90%

References

  • https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html
  • https://issues.chromium.org/issues/506689381

Related News (6 articles)

Tier D
Help Net Security57m ago
Google patches Chrome zero-day exploited in the wild (CVE-2026-11645)
→ No new info (linked only)
Tier D
Infosecurity Magazine2h ago
Google Releases Patch for Chrome Vulnerability Exploited in the Wild
→ No new info (linked only)
Tier B
BSI Advisories2h ago
[NEU] [hoch] Google Chrome: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
BleepingComputer5h ago
Google patches new Chrome zero-day flaw exploited in the wild
→ No new info (linked only)
Tier D
Heise Security6h ago
Jetzt aktualisieren: Chrome-Update schließt angegriffene Sicherheitslücke
→ No new info (linked only)
Tier D
SecurityWeek6h ago
Google Patches 5th Chrome Zero-Day Exploited in 2026
→ No new info (linked only)
CVSS 3.18.8 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
149.0.7827.103
CWECWE-125
PublishedJun 8, 2026
Last enriched2h agov4
Tags
securityexploitzero-dayhigh-severity
Trending Score78
Source articles6
Independent6
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-5281EXPKEV
CVE-2026-5281: Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the render
Trending: 151
HIGHCVE-2026-3909EXPKEV
Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Trending: 114
HIGHCVE-2026-3910EXPKEV
Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Hi
Trending: 114
HIGHCVE-2025-48595EXP
CVE-2025-48595: In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to
Trending: 82
CRITICALCVE-2026-11680EXP
CVE-2026-11680: Use after free in Media in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to execute arbitra
Trending: 66

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 8, 2026
Discovered by ZDM
Jun 9, 2026
Actively Exploited
Jun 9, 2026
Exploit Available
Jun 9, 2026
Patch Available
Jun 9, 2026
Updated: description, exploitAvailable, activelyExploited
Jun 9, 2026
Updated: affectedVersions, tags
Jun 9, 2026
Updated: description, cweIds, tags
Jun 9, 2026

Version History

v4
Last enriched 2h ago
v4Tier D2h ago

Updated description with more technical detail, added CWE-125, and included new tags related to zero-day and high-severity.

descriptioncweIdstags
via Infosecurity Magazine
v3Tier D5h ago

Updated affected versions to include 149.0.7827.102, changed severity to CRITICAL, and added new tags related to security and exploit.

affectedVersionstags
via Heise Security
v2Tier D6h ago

Updated description with more technical detail, marked as actively exploited, and noted that a patch is available.

descriptionexploitAvailableactivelyExploited
via SecurityWeek
v111h ago

Initial creation