CVE-2026-11645

HIGH(8.8)KEV

Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

Description

CVE-2026-11645 is a high-severity memory corruption vulnerability in V8, the JavaScript engine in Google Chrome (and Chromium-based browsers). It is an out-of-bounds read and write that allows a remote attacker to execute arbitrary code inside the browser sandbox via a crafted HTML page. Because exploitation only requires a victim to visit a malicious or compromised web page, CVE-2026-11645 is a classic drive-by browser vulnerability. It is rated CVSS 8.8 (High), is listed in the CISA KEV catalog, and affects Google Chrome before 149.0.7827.103. Users and administrators should update Chrome and other Chromium-based browsers immediately, since this V8 vulnerability is being actively exploited.

KEV Information

Vendor
Google
Product
Chromium V8
Date Added
June 9, 2026
Due Date
June 23, 2026
Required Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
googlechrome< 149.0.7827.103

References

Weakness Type

CWE-125: Out-of-bounds Read

CVE-2026-11645 involves CWE-125 — Out-of-bounds Read. V8 reads memory outside the bounds of an allocated buffer, which can leak adjacent memory contents such as pointers and object data that an attacker uses to defeat mitigations and prepare reliable exploitation.

Learn more: CWE-125 — Out-of-bounds Read

CWE-787: Out-of-bounds Write

CVE-2026-11645 also involves CWE-787 — Out-of-bounds Write. V8 writes data outside the intended buffer boundary, corrupting adjacent memory or control-flow data; this is the primitive that enables arbitrary code execution inside the renderer when triggered from a crafted HTML page.

Learn more: CWE-787 — Out-of-bounds Write

Impact Analysis

CVE-2026-11645 carries a CVSS 3.1 base score of 8.8 (High). Attack Vector (Network): the attack is delivered over the web via a crafted HTML page. Attack Complexity (Low): no special conditions are needed beyond serving the malicious content. Privileges Required (None): the attacker needs no account on the victim's system. User Interaction (Required): the victim must visit or be redirected to the attacker's page. Confidentiality, Integrity and Availability (High): successful exploitation yields arbitrary code execution inside the browser sandbox, allowing the attacker to read browser-accessible data, run code in the renderer, and, when chained with a sandbox escape, threaten the wider system. Although the EPSS score is modest (about 0.7%), confirmed in-the-wild exploitation of a widely deployed browser makes the practical risk high.

Exploit Maturity

CISA has added CVE-2026-11645 to the Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. The references point to the Chrome stable channel release notes and a restricted Chromium issue tracker entry rather than a public exploit, and the EPSS score is about 0.7% (49th percentile). Nonetheless, Google's release of an emergency fix and CISA's KEV listing indicate that working exploits are in use against Chrome users, so updating promptly is essential.

Remediation

  1. Follow CISA's required action and update Google Chrome to version 149.0.7827.103 or later; restart the browser to ensure the update is applied.
  2. Update all Chromium-based browsers (such as Microsoft Edge, Brave, and Opera) to the version that incorporates the fixed V8 build.
  3. In managed environments, push the browser update through your patch management or enterprise policy and verify the deployed version across endpoints.
  4. As an interim measure, advise users to avoid untrusted links and consider enabling site isolation and strict safe-browsing protections until updates complete.
  5. As long-term hardening, keep browsers on an automatic update channel so memory-safety fixes in V8 are applied promptly (per the out-of-bounds read/write guidance).

Technical Details

The vulnerability combines CWE-125 (Out-of-bounds Read) and CWE-787 (Out-of-bounds Write) in V8: a crafted HTML page drives the JavaScript engine to access memory outside an allocated buffer's bounds, both reading adjacent memory and writing beyond the intended boundary. As reflected in the CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, the attacker serves malicious JavaScript that triggers the out-of-bounds write to corrupt engine data structures, while the out-of-bounds read helps leak the addresses needed to make exploitation reliable, resulting in arbitrary code execution inside the renderer sandbox. The unchanged scope reflects that the code execution occurs within the sandboxed renderer process unless combined with a separate sandbox-escape bug.

Frequently Asked Questions

Is CVE-2026-11645 being actively exploited?

Yes. CVE-2026-11645 is listed in CISA's Known Exploited Vulnerabilities catalog, indicating confirmed in-the-wild exploitation, and Google shipped an emergency Chrome update to address it. The EPSS score is about 0.7%, but the KEV listing is the decisive signal.

What products are affected by CVE-2026-11645?

Google Chrome before version 149.0.7827.103 is affected, as are Chromium-based browsers that use the same vulnerable V8 build until they ship the corresponding fix.

How do I fix CVE-2026-11645?

Update Google Chrome to 149.0.7827.103 or later and restart the browser. Update any other Chromium-based browsers to the release that includes the fixed V8 engine.

How severe is CVE-2026-11645?

It is rated High with a CVSS 3.1 base score of 8.8. It enables arbitrary code execution inside the browser sandbox from a crafted web page and is confirmed as actively exploited, so it should be patched without delay.

CVSS Score

8.8
HIGH(8.8)

EPSS Score

EPSS Score2.19%
EPSS Percentile81.0%

Dates

PublishedJune 9, 2026
Last ModifiedJuly 23, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.