Known Exploited Vulnerability
8.8
HIGH CVSS 3.1
CVE-2026-11645
Google Chromium V8 Out-of-Bounds Read and Write Vulnerability - [Actively Exploited]
Description

Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

INFO

Published Date :

June 9, 2026, 12:16 a.m.

Last Modified :

June 9, 2026, 7:41 p.m.

Remotely Exploit :

Yes !
CISA Notification
CISA KEV (Known Exploited Vulnerabilities)

For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild.

Description :

Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action :

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Known Ransomware Campaign Use:

Unknown

Notes :

https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html ; https://issues.chromium.org/issues/506689381 ; https://nvd.nist.gov/vuln/detail/CVE-2026-11645

Affected Products

The following products are affected by CVE-2026-11645 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Google chrome
2 Google chrome
1 Microsoft windows
2 Microsoft edge_chromium
1 Linux linux_kernel
1 Apple macos
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 HIGH 134c704f-9b21-4f2e-91b3-4a467353bcc0
Solution
Update Google Chrome to patch memory corruption vulnerabilities in V8.
  • Update Google Chrome to version 149.0.7827.103 or later.
  • Avoid opening untrusted HTML pages.
Public PoC/Exploit Available at Github

CVE-2026-11645 has a 3 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2026-11645.

URL Resource
https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html Release Notes Vendor Advisory
https://issues.chromium.org/issues/506689381 Permissions Required
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-11645 US Government Resource
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-11645 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-11645 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Agent-native CVE intelligence as a hosted MCP server: ~332k vulnerabilities fused from NVD, CISA KEV, FIRST EPSS, OSV/GHSA and SSVC, ranked exploitation-first, with a CVE-claim fact-checker that catches the CVEs your agent makes up.

ai-security bug-bounty claude cve epss infosec kev llm mcp mcp-server model-context-protocol nvd security security-research ssvc threat-intelligence vulnerability-intelligence vulnerability-management

Updated: 1 week, 6 days ago
0 stars 0 fork 0 watcher
Born at : June 14, 2026, 10:06 a.m. This repo has been linked 19 different CVEs too.

None

Updated: 2 weeks, 2 days ago
0 stars 0 fork 0 watcher
Born at : June 12, 2026, 10:34 a.m. This repo has been linked 11 different CVEs too.

CVE-2026-11645

HTML

Updated: 2 weeks, 3 days ago
1 stars 0 fork 0 watcher
Born at : June 11, 2026, 3:17 p.m. This repo has been linked 1 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-11645 vulnerability anywhere in the article.

  • The Hacker News
Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs

A high-severity flaw in Amazon Q Developer let a malicious repository run commands and steal a developer's cloud credentials. The path was short: a developer opens the repo, trusts the workspace, and ... Read more

Published Date: Jun 26, 2026 (2 days, 17 hours ago)
  • The Hacker News
New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries

A flaw in the Linux kernel's traffic-control subsystem can let a local unprivileged user gain root on affected systems. CVE-2026-46331, nicknamed "pedit COW," is an out-of-bounds write in the packet-e ... Read more

Published Date: Jun 26, 2026 (2 days, 18 hours ago)
  • The Hacker News
CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical remote code execution vulnerability impacting PTC Windchill PDMlink and PTC FlexPLM enterprise Product Dat ... Read more

Published Date: Jun 26, 2026 (2 days, 19 hours ago)
  • The Hacker News
New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets

DirtyClone is a new Linux kernel privilege escalation in the DirtyFrag family. JFrog Security Research published a working exploit walkthrough for the flaw on June 25, the first public demonstration f ... Read more

Published Date: Jun 26, 2026 (2 days, 19 hours ago)
  • The Hacker News
Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks

The Russian state-sponsored threat actor known as Turla has been attributed to a previously undocumented .NET backdoor called STOCKSTAY that has been deployed against government and military organizat ... Read more

Published Date: Jun 26, 2026 (3 days ago)
  • TheCyberThrone
Google Chrome 149 Security Update: 18 Vulnerabilities Patched

June 25, 2026Google has shipped a Stable Channel update fixing 18 security vulnerabilities in Chrome — four rated Critical, fourteen rated High. None of the 18 show evidence of active exploitation at ... Read more

Published Date: Jun 25, 2026 (3 days, 15 hours ago)
  • The Hacker News
Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access

An unknown threat actor exploited a recently disclosed high-severity security flaw impacting Cisco Catalyst SD-WAN as a zero-day at least two months before it was publicly disclosed, according to new ... Read more

Published Date: Jun 25, 2026 (4 days, 1 hour ago)
  • The Hacker News
CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation of a critical security flaw impacting Lantronix EDS5000 Series devices, urging Federal Civilia ... Read more

Published Date: Jun 24, 2026 (4 days, 14 hours ago)
  • The Hacker News
Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root

Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Editio ... Read more

Published Date: Jun 24, 2026 (5 days ago)
  • The Hacker News
Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants

Cybersecurity researchers have disclosed details of four vulnerabilities in Dify, an open-source agentic workflow platform with more than 146,000 GitHub stars, that could allow attackers to stealthily ... Read more

Published Date: Jun 22, 2026 (6 days, 15 hours ago)
  • The Hacker News
Stop Your Legacy Infrastructure from Hijacking Your AI Agents

Earlier this month, I spoke at the Gartner Security & Risk Management Summit about a blind spot most security programs are still not accounting for - how attackers are circumventing AI security progra ... Read more

Published Date: Jun 22, 2026 (6 days, 19 hours ago)
  • The Hacker News
AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network

A new malware family is turning forgotten home routers into a distributed reconnaissance and proxy network, not the DDoS botnet these devices usually end up in. QiAnXin's XLab calls it AryStinger and ... Read more

Published Date: Jun 22, 2026 (1 week ago)
  • The Hacker News
Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that's installed on about 100,000 sites. The vulnerability, tracked as CVE-2026-4020 (CVSS scor ... Read more

Published Date: Jun 20, 2026 (1 week, 1 day ago)
  • The Hacker News
AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution

Microsoft researchers have detailed an exploit chain, named AutoJack, that turns an AI browsing agent into a delivery vehicle for remote code execution. Steer the agent to load an attacker's web page, ... Read more

Published Date: Jun 19, 2026 (1 week, 2 days ago)
  • The Hacker News
Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone

Apple has updated its Beats Studio Buds wireless earbuds to patch a high-severity vulnerability that could be exploited by nearby hackers to eavesdrop on users. The vulnerability, tracked as CVE-2025- ... Read more

Published Date: Jun 19, 2026 (1 week, 3 days ago)
  • The Hacker News
F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution

Ravie LakshmananJun 18, 2026Vulnerability / Cloud Security F5 has released security updates to address two critical security flaws in NGINX Open Source that could be exploited to achieve code execut ... Read more

Published Date: Jun 18, 2026 (1 week, 3 days ago)
  • The Hacker News
ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories

The internet did not break this week. It got used exactly as designed, which is worse.Searches were siphoned through shady browser add-ons. AI chat links turned into malware delivery paths. macOS atta ... Read more

Published Date: Jun 18, 2026 (1 week, 3 days ago)
  • The Hacker News
INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023

Cybersecurity researchers have charted the evolution of INC from an nascent ransomware-as-a-service (RaaS) operation to one of the most prolific cybercrime groups in 2026, claiming no less than 830 vi ... Read more

Published Date: Jun 18, 2026 (1 week, 3 days ago)
  • The Hacker News
DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic

Threat actors associated with the DragonForce ransomware have been observed using a custom Go-based remote access trojan (RAT) called Backdoor.Turn to conceal command-and-control (C2) traffic inside M ... Read more

Published Date: Jun 18, 2026 (1 week, 3 days ago)
  • The Hacker News
Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

Microsoft has formally disclosed that it's working to release a patch to address a Defender zero-day codenamed RoguePlanet. The vulnerability has now been assigned the CVE identifier CVE-2026-50656 (C ... Read more

Published Date: Jun 17, 2026 (1 week, 4 days ago)

The following table lists the changes that have been made to the CVE-2026-11645 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • Modified Analysis by [email protected]

    Jun. 09, 2026

    Action Type Old Value New Value
    Added Reference Type CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-11645 Types: US Government Resource
  • CVE CISA KEV Update by 9119a7d8-5eab-497f-8521-727c672e3725

    Jun. 09, 2026

    Action Type Old Value New Value
    Added Date Added 2026-06-09
    Added Due Date 2026-06-09
    Added Required Action 2026-06-09
    Added Vulnerability Name 2026-06-09
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Jun. 09, 2026

    Action Type Old Value New Value
    Added Reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-11645
  • Initial Analysis by [email protected]

    Jun. 09, 2026

    Action Type Old Value New Value
    Added CPE Configuration AND OR *cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* versions up to (excluding) 149.0.7827.103 OR cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
    Added Reference Type Chrome: https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html Types: Release Notes, Vendor Advisory
    Added Reference Type Chrome: https://issues.chromium.org/issues/506689381 Types: Permissions Required
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Jun. 09, 2026

    Action Type Old Value New Value
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
    Added CWE CWE-125
    Added CWE CWE-787
  • New CVE Received by [email protected]

    Jun. 09, 2026

    Action Type Old Value New Value
    Added Description Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
    Added Reference https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html
    Added Reference https://issues.chromium.org/issues/506689381
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.