• News/
  • bleepingcomputer-20260609065627

Google patches new Chrome zero-day flaw exploited in the wild

BleepingComputer
·
Sergiu Gatlan
·
Published Jun 9, 2026
·
Updated

Google has released emergency updates to patch another Chrome zero-day vulnerability that has been exploited in the wild, the fifth such flaw patched since the start of the year. "Google is aware that an exploit for CVE-2026-11645 exists in the wild," the company said in a Monday security advisory. The company fixed the zero-day for users in the Stable Desktop channel, with patched versions rolling out worldwide to Windows (149.0.7827.102), Mac (149.0.7827.103), and Linux (149.0.7827.102) systems two weeks after an anonymous security researcher reported it to Google. While Google says the security update could take days or weeks to reach all Chrome users, the update was available immediately when BleepingComputer checked for updates earlier today. Users who prefer not to manually update their web browser can rely on Chrome to automatically check for updates and install them during the next launch.

​This high-severity zero-day vulnerability (CVE-2026-11645) stems from an out-of-bounds read and write weakness in the Chrome V8 JavaScript engine, which remote attackers can exploit via crafted HTML pages to execute arbitrary code inside the web browser's sandbox. Successful exploitation enables them to access data beyond the memory buffer via heap corruption, exposing sensitive information or triggering a crash. Besides unauthorized access to out-of-bounds memory, the now-patched zero-day bug could also be exploited to bypass protection mechanisms such as ASLR, making it easier ...

Read full article

Affected Software

3 affected components
Google Chrome=149.0.7827.102
Google Chrome=149.0.7827.103
Google V8 JavaScript engine
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a newly discovered zero-day vulnerability in Google Chrome that has been exploited in the wild.

2

What security implications are discussed?

The article highlights the urgent need for users to update Chrome to protect against active exploitation of the vulnerability CVE-2026-11645.

3

What products or software are affected?

The affected software includes Google Chrome and the Google V8 JavaScript engine.

4

How many zero-day flaws has Google patched this year?

Google has patched five zero-day vulnerabilities in Chrome since the beginning of the year.

5

When was this vulnerability first reported?

This vulnerability, CVE-2026-11645, was reported on June 9, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203