HIGH: Chrome V8 Zero-Day CVE-2026-11645 Under Active Exploitation, Patch Today
Google confirmed active in the wild exploitation of CVE-2026-11645, an out-of-bounds read and write vulnerability in Chrome V8 with a CVSS score of 8.8. The fifth Chrome zero day patched in 2026 lets attackers run code inside the browser sandbox via a crafted HTML page. Update to Chrome 149.0.7827.102 or .103 immediately and force a relaunch across the fleet.