---
schema: 1
kind: vulnerability
title: "CVE-2026-11645 — Google Chrome V8 out-of-bounds read/write exploited in the wild, added to CISA KEV"
headline: "CVE-2026-11645 — Google Chrome V8 out-of-bounds read/write exploited in the wild, added to CISA KEV"
summary: "Google patched CVE-2026-11645 (CVSS 8.8), an out-of-bounds read and write in the V8 engine, in Chrome 149.0.7827.103; a crafted HTML page achieves code execution inside the renderer sandbox (Chrome, 2026-06-08)."
discovered_at: "2026-06-10T05:00:09Z"
event_date: 2026-06-08
run_id: 2026-06-10-c84347b2
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - actively-exploited
  - rce
  - cisa-kev
  - zero-day
regions:
  - global
sectors:
  - public-sector
entities: []
cves:
  - id: CVE-2026-11645
    cvss: "8.8"
    epss: null
    type: rce
    vector: user-interaction
    auth: pre-auth
    status:
      - exploited
      - cisa-kev
      - patch-available
sources:
  - url: "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html"
    publisher: "Chrome, 2026-06-08"
    role: primary
closed_sources: []
evidence:
  - quote: "Google patched CVE-2026-11645 (CVSS 8.8), an out-of-bounds read and write in the V8 engine, in Chrome 149.0.7827.103; a crafted HTML page achieves code execution inside the renderer sandbox (Chrome, 2026-06-08)."
    publisher: ctipilot v2 brief (migrated)
verification: single-source
sourcing_note: "migration: evidence backfilled from v2 brief body (item predates the Evidence footer field)"
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-06-10.md
---

Google patched CVE-2026-11645 (CVSS 8.8), an out-of-bounds read and write in the V8 engine, in Chrome 149.0.7827.103; a crafted HTML page achieves code execution inside the renderer sandbox ([Chrome, 2026-06-08](https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html)). The bug was exploited in the wild before patching and CISA added it to the KEV catalog on 9 June; per the Chrome advisory it affects Chromium-based browsers including Edge and Opera ([Chrome, 2026-06-08](https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html)). The KEV listing is the operational signal here — confirmed active exploitation of a one-click browser bug (T1189, T1203). Update Chrome/Edge/Opera to 149.0.7827.103+ across the estate.
