Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3345 articles · 209390 vulns · 37/41 feeds (7d)
← Back to list
8.8
CVE-2026-11645EXPLOITEDPATCHED
google · chrome

CVE-2026-11645: Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitra

Description

Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Affected Products

VendorProductVersions
googlechrome149.0.7827.103

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
applemacoscve_cpe95%
googlechromecert_advisory90%
linuxlinux_kernelcve_cpe95%
microsoftwindowscve_cpe95%

References

  • https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html
  • https://issues.chromium.org/issues/506689381

Related News (16 articles)

Tier D
BleepingComputer2h ago
Google warns of new Chrome zero-day flaw exploited in attacks
→ No new info (linked only)
Tier A
Microsoft MSRC80d ago
Chromium: CVE-2026-11645 Out of bounds memory access in V8
→ No new info (linked only)
Tier B
CERT-FR81d ago
Bulletin d'actualité CERTFR-2026-ACT-026 (15 juin 2026)
→ No new info (linked only)
Tier D
Help Net Security82d ago
Week in review: Exploited Check Point VPN zero-day, Oracle PeopleSoft servers under attack
→ No new info (linked only)
Tier B
CCCS Canada84d ago
Microsoft Edge security advisory (AV26-591)
→ No new info (linked only)
Tier E
Hacker News86d ago
High severity Chrome CVE-2026-11645
→ No new info (linked only)
Tier D
SecurityWeek86d ago
No Patch Planned for Exploited Arista EOS Vulnerability
→ No new info (linked only)
Tier B
CCCS Canada87d ago
Google Chrome security advisory (AV26-561)
→ No new info (linked only)
Tier D
The Hacker News87d ago
Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now
→ No new info (linked only)
Tier D
Help Net Security87d ago
Google patches Chrome zero-day exploited in the wild (CVE-2026-11645)
→ No new info (linked only)
Tier D
Infosecurity Magazine87d ago
Google Releases Patch for Chrome Vulnerability Exploited in the Wild
→ No new info (linked only)
Tier B
BSI Advisories87d ago
[NEU] [hoch] Google Chrome: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
BleepingComputer87d ago
Google patches new Chrome zero-day flaw exploited in the wild
→ No new info (linked only)
Tier D
Heise Security87d ago
Jetzt aktualisieren: Chrome-Update schließt angegriffene Sicherheitslücke
→ No new info (linked only)
Tier D
SecurityWeek87d ago
Google Patches 5th Chrome Zero-Day Exploited in 2026
→ No new info (linked only)
Tier B
CERT-FR87d ago
Multiples vulnérabilités dans Google Chrome (09 juin 2026)
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.8 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
149.0.7827.103
PublishedJun 8, 2026
Last enriched80d agov7
Tags
securityexploitzero-dayhigh-severitymultiple vulnerabilitieschromium-based
Trending Score107🔥
Source articles16
Independent11
Info Completeness9/14
Missing: epss, cwe, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-85046
CVE-2026-85046: Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside
Trending: 65
CRITICALCVE-2026-84325
CVE-2026-84325: Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging s
Trending: 61
CRITICALCVE-2026-84353
CVE-2026-84353: Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leve
Trending: 55
CRITICALCVE-2026-85050
CVE-2026-85050: Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute
Trending: 54
CRITICALCVE-2026-84324
CVE-2026-84324: Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outs
Trending: 52

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 8, 2026
Discovered by ZDM
Jun 9, 2026
Updated: description, exploitAvailable, activelyExploited
Jun 9, 2026
Updated: affectedVersions, tags
Jun 9, 2026
Updated: description, cweIds, tags
Jun 9, 2026
Updated: severity, tags
Jun 9, 2026
Updated: affectedVersions
Jun 9, 2026
Actively Exploited
Jun 10, 2026
Exploit Available
Jun 10, 2026
Patch Available
Jun 10, 2026
Updated: tags
Jun 15, 2026

Version History

v7
Last enriched 80d ago
v7Tier A80d ago

Updated vendor to Microsoft and added product Edge, along with a new tag 'chromium-based'.

tags
via Microsoft MSRC
v6Tier B87d ago

Added affected version 149.0.7827.102 for Linux and updated patch availability to null.

affectedVersions
via CCCS Canada
v5Tier B87d ago

Added affected version 149.0.7827.102, updated severity to MEDIUM, and added new tags for multiple vulnerabilities.

severitytags
via CERT-FR
v4Tier D87d ago

Updated description with more technical detail, added CWE-125, and included new tags related to zero-day and high-severity.

descriptioncweIdstags
via Infosecurity Magazine
v3Tier D87d ago

Updated affected versions to include 149.0.7827.102, changed severity to CRITICAL, and added new tags related to security and exploit.

affectedVersionstags
via Heise Security
v2Tier D87d ago

Updated description with more technical detail, marked as actively exploited, and noted that a patch is available.

descriptionexploitAvailableactivelyExploited
via SecurityWeek
v187d ago

Initial creation