INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ATTENTION: This report is based on previous data. New intelligence sources have been linked and the Executive Summary and Mitigations need to be re-synthesized.

Chrome V8 Zero-Day Exploited in the Wild Patch

| 2026-06-09 11:58 MEDIUM HIGH
Executive Summary AI-generated
The high-severity vulnerability, tracked as CVE-2026-11645 (CVSS score: 8.8), has been described as an out-of-bounds memory access in V8, Google Chrome's JavaScript and WebAssembly engine. This flaw allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. As is customary in these cases, Google acknowledged that an exploit for CVE-2026-11645 exists in the wild but stopped short of sharing additional specifics to ensure majority users are updated with a fix and prevent further exploitation. Users are advised to update their Chrome browser to versions 149.0.7827.102/.103 for Windows and Apple macOS, and 149.0.7827.102 for Linux, or apply the security updates as and when they become available.
Technical Mitigations AI-generated
* Use a sandboxed environment: Ensure that your system is isolated from other applications and services to prevent attackers from executing arbitrary code inside the browser. * Keep Chrome up-to-date: Regularly update your Chrome browser to ensure you have the latest security patches, including fixes for CVE-2026-11645. * Avoid using outdated extensions or plugins: Refrain from installing or updating extensions or plugins that may be vulnerable to exploitation of this vulnerability.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-3909CVE-2026-3909 CVE-2026-2441CVE-2026-2441 CVE-2024-0519CVE-2024-0519 CVE-2026-5281CVE-2026-5281 CVE-2026-3910CVE-2026-3910 CVE-2026-11645CVE-2026-11645
Target & Sectors
Global Scope
Incident Timeline
‎2025/06/09
Threat actors exploited an eight zero-day vulnerability in Google's Chrome browser.
organisation Threat Analysis Group
‎April 27
Google released a patch for the Chrome vulnerability exploited in the wild on April 27.
‎April 27, 2026
Google released a patch for the Chrome vulnerability exploited in the wild on April 27, 2026.
‎June 8
Google released a security bulletin on June 8, which included fixes for 17 critical vulnerabilities and 55 high-severity ones.
general_metric 17 critical vulnerabilities
general_metric 55 severity ones
‎Jun 09, 2026
Google released a patch for the Chrome vulnerability exploited in the wild on June 9, 2026.
‎2026/06/09
BleepingComputer discovered and released a patch for the Chrome vulnerability exploited in the wild.
organisation BleepingComputer
‎2026/06/09
Google released a patch for the Chrome vulnerability exploited in the wild, CVE-2026-11645.
infrastructure Windows
infrastructure Linux
infrastructure 149.0.7827
organisation Windows, Mac
organisation Google Chrome
financial $55,000 Linux
organisation CVE-2026
organisation HTML
organisation Chrome
organisation WebAssembly
organisation Windows/Mac
organisation Windows and Mac
infrastructure Macos
organisation Stable Desktop
organisation NIST
organisation National Vulnerability Database
organisation NVD
organisation Google
organisation Vulnerability / Browser Security
organisation Mijansk786 / Wachiwit / Shutterstock.com Read
organisation AI Unearths Decades of Flaws
organisation Malwarebytes Browser Guard
organisation Chrome’s V8
organisation Chromium
organisation Microsoft Edge, Brave,
organisation WebGPU
organisation Skia 2D
organisation PDF
organisation CSS
organisation CVE-2024-0519
organisation EDR
Tactical Metrics
Metrics
infrastructure
‎149.0.7827
Software Version
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Macos
Affected Product
Metrics
infrastructure
‎Linux
Affected Product
Metrics
financial
55,000
Linux
Intelligence Sources