logo

Google patches Chrome zero-day exploited in the wild (CVE-2026-11645)

ID: 8e722967-8f28-5a8e-a440-b1b91fba8cfd

STIX ID: report--8e722967-8f28-5a8e-a440-b1b91fba8cfd

Feed Name: Help Net Security

Threat Score
85/100

Date Published: 2026-06-09

Date Updated: 2026-06-09

Author: Sinisa Markovic

...
...

Google patched a high-severity zero-day (CVE-2026-11645) in Chrome’s V8 JavaScript engine that allows out-of-bounds read/write and can enable remote code execution; the flaw was reported as being exploited in the wild and fixed in Chrome 149.0.7827.102/.103 for Windows and macOS and 149.0.7827.102 for Linux. The bug was reported on April 27, 2026, by an anonymous researcher who received a $55,000 bounty, and Google limited disclosure pending user updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.