logo

Google patches new Chrome zero-day flaw exploited in the wild

ID: bef48600-45cf-5543-8ba1-5edced199947

STIX ID: report--bef48600-45cf-5543-8ba1-5edced199947

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2026-06-09

Date Updated: 2026-06-09

Author: Sergiu Gatlan

...
...

Google released emergency updates to patch a high-severity Chrome zero-day (CVE-2026-11645) actively exploited in the wild; the flaw is an out-of-bounds read/write in the V8 JavaScript engine that can enable arbitrary code execution from crafted web content and aid in bypassing mitigations like ASLR. Patched Stable channel versions for Windows, macOS, and Linux were issued, and Google limited disclosure while updates roll out; the advisory also notes several other zero-days addressed earlier in the year.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.