cbcvebase.
CVE-2026-11645
published 2026-06-09

CVE-2026-11645: Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted…

PriorityP186high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-06-23
Exploited in the wild
EPSS
1.65%
73.9th percentile
Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Affected

4 ranges
VendorProductVersion rangeFixed in
googlechrome< 149.0.7827.103149.0.7827.103
googlechrome>= 149.0.7827.103 < 149.0.7827.103149.0.7827.103
googlechrome_desktop
paloaltoprisma_browser

Detection & IOCsextracted from sources · hover to see the quote

versionGoogle Chrome prior to 149.0.7827.103
  • CVE-2026-11645 is actively exploited in the wild via crafted HTML pages targeting Chrome's V8 JavaScript/WebAssembly engine (out-of-bounds read/write). Monitor for exploitation attempts delivered through browser-rendered HTML.
  • Flag Chrome browser versions below 149.0.7827.102 (Linux) or 149.0.7827.103 (Windows/macOS) as unpatched and vulnerable to CVE-2026-11645.
  • Chromium-based browsers (Microsoft Edge, Brave, Opera, Vivaldi) share the same V8 engine and are also vulnerable until their respective vendors ship patches; include these in endpoint detection scope.
  • CISA added CVE-2026-11645 to the KEV catalog; FCEB agencies must remediate by June 23, 2026. Treat any unpatched Chrome instance in a federal or critical-infrastructure environment as high-priority.
  • Chromium bug tracker ID 506689381 corresponds to CVE-2026-11645; use this ID to cross-reference patch commits and diff analysis for signature development.
  • ·Google has not publicly disclosed technical specifics of the exploit or indicators of compromise to limit further exploitation while users patch.
  • ·Exploitation is sandboxed (code execution inside the Chrome sandbox); a full compromise likely requires a sandbox escape chained with this vulnerability.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vulncheck8.8HIGH
cisa8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.