Chrome V8 Zero-Day CVE-2026-11645 Being Exploited in the Wild – Update Immediately
Google has pushed out security updates that fix 74 flaws in Chrome, one of which is already being abused by attackers in the wild. The most serious of these is tracked as CVE-2026-11645 and carries a CVSS score of 8.8. This issue stems from an out-of-bounds memory access bug in V8, Chrome’s JavaScript and WebAssembly execution engine.
According to the U.S. National Vulnerability Database, the flaw involves both out-of-bounds reads and writes in V8 that affect versions of Google Chrome older than 149.0.7827.103. Exploitation can allow a remote actor to run arbitrary code inside the browser’s sandbox when a victim opens a specially crafted HTML page.
A security researcher who goes by the handle “303f06e3” reported the vulnerability to Google on April 27, 2026, and received a $55,000 bug bounty for responsible disclosure. Google confirmed that an exploit targeting CVE-2026-11645 is circulating, but did not publish technical specifics so users have time to upgrade and to limit additional attacks.
This release marks the fifth Chrome zero-day that Google has said was actively exploited this year. Earlier in 2026, the company addressed CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, and CVE-2026-5281.
To protect your system, update Chrome to the fixed builds: 149.0.7827.102/.103 for Windows and Apple macOS, and 149.0.7827.102 for Linux. To force Chrome to check for and apply the update, go to More > Help > About Google Chrome and click Relaunch.
Users of other Chromium-based browsers – including Microsoft Edge, Brave, Opera, and Vivaldi – should watch for and install their vendors’ corresponding patches as they become available.