Skip to main content
Mallory
Back to intelligence
actively-exploited-vulnerabilityendpoint-software-vulnerabilitywidely-deployed-product-advisory

Google Chrome Patches Actively Exploited V8 Out-of-Bounds Flaw

Updated 33m agoFirst seen Jun 9, 202617 sources

Google released an urgent Chrome desktop update to fix 74 security issues, including CVE-2026-11645, a high-severity out-of-bounds memory access vulnerability in the V8 JavaScript engine. Google said an exploit for the flaw exists in the wild, making it the most pressing issue in the release. The update affects Chrome on Windows, macOS, and Linux, and Google limited technical details for some bugs until more users receive the patch.

The release also addresses multiple additional memory-safety flaws, including use-after-free bugs in components such as Ozone, Bluetooth, and tab strips. HKCERT separately published an advisory covering multiple Chrome vulnerabilities, reinforcing the breadth of the fixes. Organizations are being urged to update Chrome immediately and ensure browser restarts are completed so the patched version is applied across managed endpoints.

Share:
Google Chrome Patches Actively Exploited V8 Out-of-Bounds Flaw
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Jun 9, 20261d ago

Google releases Chrome update fixing exploited V8 flaw CVE-2026-11645

Google released an urgent Chrome desktop security update addressing CVE-2026-11645, a high-severity out-of-bounds memory access vulnerability in the V8 JavaScript engine. Google said an exploit for the flaw exists in the wild and noted the update also includes 74 security fixes affecting Windows, macOS, and Linux desktop platforms.

Chrome Security Update: Exploit in the Wild Fixed
Apr 27, 20261mo ago

Researcher reports Chrome zero-day CVE-2026-11645 to Google

Google said researcher "303f06e3" reported CVE-2026-11645, an out-of-bounds memory access flaw in the V8 engine, on 2026-04-27. The company awarded a $55,000 bug bounty for the finding.

Chrome's zero-day Whac-A-Mole continues with fifth exploited bug of the year
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

99 LINKEDOpen in app
Vulnerabilities
79 linked
Out-of-bounds read/write in Google Chrome V8Use-after-free in Google Chrome CSS (CSSFontFeatureValuesMap)RCE in Google Chrome V8 via crafted HTML pageOut-of-bounds write in Skia in Google ChromeUse-after-free in Dawn in Google ChromeInteger Overflow in libyuv in Google ChromeHeap buffer overflow in Chrome GPU on AndroidOut-of-bounds read in WebRTC in Google ChromeType Confusion in Bindings in Google ChromeRCE in Google Chrome SVGUse-after-free in V8 in Google ChromeSandbox escape race condition in Google Chrome Network on MacUse-after-free in Google Chrome NetworkUse-after-free in Ozone in Google ChromeUse-after-free in Google Chrome ExtensionsUse-after-free in Google Chrome PDFUse-after-free in Google Chrome ServiceWorkerSite isolation bypass in Google Chrome ExtensionsUse-after-free in Ozone in Google ChromeUse-after-free in Google Chrome ServiceWorkerUse-after-free in V8 in Google ChromeOut-of-bounds memory access in Google Chrome V8Cross-origin data leak in Dawn in Google Chrome on macOSSandbox escape via integer overflow in Media in Google Chrome on MacSandbox escape in Google Chrome Views on LinuxOut-of-bounds read/write in Media in Google Chrome on MacUse-after-free in Google Chrome CameraCapture on MacUse-after-free in Google Chrome Guest ViewUse-after-free in Google Chrome ViewTransitionsCross-origin data leak in Google Chrome New Tab PageUse-after-free in Read Anything in Google ChromeCross-origin data leak in Google Chrome PasswordsUse-after-free in Chrome Views sandbox escape on WindowsOut-of-bounds read in Skia in Google ChromeUse-after-free in Skia in Google ChromeUninitialized Use in Video in Google Chrome on WindowsUse-after-free in Views in Google Chrome on MacUse-after-free in Bluetooth in Google Chrome on MacUse-after-free in Bluetooth in Google Chrome on MacUse-after-free in Google Chrome Autofill on WindowsSandbox escape in Google Chrome UIUI Spoofing in Google Chrome InputSite Isolation Bypass in Google Chrome PluginsSite Isolation Bypass in Google Chrome ExtensionsUse-after-free in File Input in Google ChromeUse-after-free in Gamepad in Google ChromeUse-after-free in Media in Google Chrome on WindowsUse-after-free sandbox escape in Aura in Google Chrome on WindowsUse-after-free in Codecs in Google Chrome for WindowsUse-after-free sandbox escape in Google Chrome Web AppsUse-after-free in FullScreen in Google Chrome on WindowsInteger overflow in Google Chrome UI on LinuxUse-after-free in Navigation in Google ChromeUse-after-free in Proxy in Google ChromeUninitialized Use in Chrome Codecs leads to cross-origin data leakUse-after-free in Compositing in Google Chrome on MacSite Isolation Bypass in Google Chrome PasswordsOut-of-bounds read in Media in Google Chrome on ChromeOSUse-after-free in Bluetooth in Google Chrome on MacUse-after-free in Printing in Google Chrome on AndroidUse-after-free in Google Chrome PrintingUse-after-free in Google Chrome TracingUse-after-free in Google Chrome WebCodecsUse-after-free in Views in Google Chrome on LinuxUI Spoofing in Google Chrome Guest ViewCross-origin data leak in Google Chrome MediaCapture on MacSandbox escape in Google Chrome New Tab PageInteger overflow in libyuv in Google ChromeUse-after-free in Google Chrome TabStripUse-after-free in Payments in Google ChromeOut-of-bounds Read in Dawn in Google ChromeUse-after-free in Dawn in Google Chrome on MacSandbox escape in Google Chrome Dawn on Linux and ChromeOSCross-origin data leak in Google Chrome Network policy enforcementUse-after-free in InterestGroups in Google ChromeUse-after-free in Google Chrome Payments on MacUse-after-free in Bluetooth in Google Chrome on MacUse-after-free in Ozone in Google Chrome on LinuxUse-after-free in Bluetooth in Google Chrome on Windows
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.