GOOGLE PATCHES EXPLOITED HIGH-SEVERITY CHROME V8 VULNERABILITY
Google has released a security patch for a high-severity vulnerability in its Chrome browser that is being actively exploited. The flaw, tracked as CVE-2026-11645, is an out-of-bounds read and write bug in Chrome's V8 engine. It carries a severity score of 8.8 out of 10 and allows remote attackers to execute arbitrary code inside a sandbox via a crafted HTML page. Google confirmed in its advisory that an exploit for the vulnerability exists in the wild.
The bug affects versions of Chrome prior to 149.0.7827.103 and has been patched in the Stable Desktop channel. Updated versions are now available for Windows (149.0.7827.102), Mac (149.0.7827.103), and Linux (149.0.7827.102). Google stated it may restrict access to bug details and links until a majority of users have received the fix. The company added that restrictions may also remain in place if the bug exists in a third-party library that other projects depend on but have not yet patched. Google paid the reporting researcher a $55,000 bounty for the discovery.
CVE-2026-11645 is the fifth exploited Chrome vulnerability of the year. Google noted that patches typically take several weeks to roll out globally, though most browsers are generally updated by the time an advisory is published. Users who wish to verify their installation can navigate to chrome://settings/help in the address bar, which will prompt Chrome to check for and install any available updates. The advisory covered dozens of flaws in total, of which the V8 bug was the most severe.