Google patches Chrome zero-day exploited in the wild (CVE-2026-11645)
ID: 8e722967-8f28-5a8e-a440-b1b91fba8cfd
STIX ID: report--8e722967-8f28-5a8e-a440-b1b91fba8cfd
Feed Name: Help Net Security
Threat Score
Google patched a high-severity zero-day (CVE-2026-11645) in Chrome’s V8 JavaScript engine that allows out-of-bounds read/write and can enable remote code execution; the flaw was reported as being exploited in the wild and fixed in Chrome 149.0.7827.102/.103 for Windows and macOS and 149.0.7827.102 for Linux. The bug was reported on April 27, 2026, by an anonymous researcher who received a $55,000 bounty, and Google limited disclosure pending user updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
