LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-11645: Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 9, 2026
CVSS 8.8 · High⚠ Actively exploited (CISA KEV)
8.8
CVSS score
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 23, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-11645 to its Known Exploited Vulnerabilities catalog on Jun 9, 2026, with a federal patch deadline of Jun 23, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

This vulnerability is an out-of-bounds read and write flaw in the V8 JavaScript engine used by Google Chromium. A remote attacker can trigger it with a crafted HTML page to execute arbitrary code inside the browser sandbox. The issue affects any browser that embeds Chromium, including Google Chrome, Microsoft Edge, and Opera.

How it works

The weakness belongs to the out-of-bounds write (CWE-787) and out-of-bounds read (CWE-125) classes. In these flaws, code reads or writes memory outside the intended buffer boundaries. An attacker supplies a specially formed HTML page that causes V8 to perform the invalid access during JavaScript execution.

Am I affected? How to find it in your systems

Inventory all Chromium-based browsers and any embedded Chromium components in enterprise applications. Check installed browser versions and configurations against the vendor advisory for the affected range. Typical deployment locations include user workstations, virtual desktop images, and any internal web applications that ship a browser runtime.

How to remediate

Apply the vendor-supplied update for the affected Chromium V8 component. After patching, verify that the update has been deployed across all browser instances and embedded runtimes. Follow any additional hardening steps listed in the vendor advisory for this class of memory-safety issue.

If you can't patch immediately

Apply mitigations per the vendor instructions. Where mitigations are unavailable, discontinue use of the product. For cloud-hosted instances, follow applicable BOD 22-01 guidance. Segment browser traffic, restrict rendering of untrusted content, and increase monitoring of renderer processes until patches can be applied.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to breaches. You can run a free exposure scan of your email addresses to check known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedGoogle · Chromium V8
WeaknessCWE-125
CVSS base score8.8 (High)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
PublishedJun 9, 2026
Added to CISA KEVJun 9, 2026
Federal patch deadlineJun 23, 2026
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities