CVE-2026-11645: Chrome V8 Zero-Day — OOB Read/Write In-Browser RCE Analysis

Technical analysis of the Chrome V8 out-of-bounds read/write memory corruption zero-day exploited in targeted surveillance campaigns.

CVE-2026-11645: Chrome V8 Zero-Day — OOB Read/Write In-Browser RCE Analysis
📌
Security Roundup Series: Week of June 12, 2026 • 4 min read deep dive
🚨
Threat Intelligence & Technical Specs: CVE ID: CVE-2026-11645 Severity: CVSS 8.8 Status: ⚠️ Actively Exploited Browser In-The-Wild Zero-Day Target Component: Google Chrome V8 Engine

This post is part of the Week of June 12, 2026 Security Roundup.


Vulnerability Overview

CVE-2026-11645 is an out-of-bounds read and write vulnerability in Chrome's V8 JavaScript/WebAssembly engine, rated CVSS 8.8 High. Google confirmed active exploitation in the wild prior to patching. CISA added it to the Known Exploited Vulnerabilities catalog on June 9, 2026, with FCEB agencies required to remediate by June 23.

CVE: CVE-2026-11645
CVSS v3.1: 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CWE: CWE-787 (Out-of-bounds Write) / CWE-125 (Out-of-bounds Read)
Component: V8 JavaScript/WebAssembly engine
Fixed in: Chrome 149.0.7827.102/.103 (Windows/macOS), 149.0.7827.102 (Linux)
Patch date: June 8, 2026
CISA KEV: June 9, 2026 | Remediation deadline: June 23, 2026

Technical Analysis

V8's JIT compiler performs aggressive optimizations including type specialization and bounds-check elimination. When a crafted JavaScript pattern tricks V8's optimizer into eliminating a bounds check on a typed array operation, subsequent reads and writes can occur outside the intended buffer boundaries in the V8 heap. The OOB access can be leveraged to corrupt adjacent objects in V8's managed heap, enabling:

  • Type confusion between V8 object types
  • Arbitrary read from V8 heap memory (disclosure of pointers, secrets)
  • Controlled write to V8 heap (overwrite function pointers, JIT stubs)
  • In-renderer RCE within the Chrome renderer sandbox

A full sandbox escape (for OS-level code execution) requires chaining with a second vulnerability—typically a Chrome sandbox escape or a Windows kernel EoP. Active exploitation chains of this type have been observed in spyware and sophisticated threat actor campaigns throughout 2026.

Attack Scenario

1. Attacker hosts or injects a crafted HTML page with malicious JavaScript
2. Victim visits the page (or is served it via malvertising, phishing, or XSS)
3. CVE-2026-11645 triggers OOB write in V8 → in-renderer code execution
4. [Optional] Sandbox escape via second vulnerability → OS-level compromise
5. Payload delivery: credential stealer, RAT, cryptominer, ransomware dropper

Exploitation artifacts to watch for:
- Chrome renderer crashes (check Event Viewer: Application log, source: Application Error)
- Unusual child processes spawned from chrome.exe or chrome --renderer
- Outbound connections from chrome.exe to unexpected IPs

Remediation

# Check current Chrome version
# Windows (PowerShell):
(Get-ItemProperty "HKLM:\SOFTWARE\Google\Chrome\BLBeacon").version
# Target: 149.0.7827.102 or higher

# Force Chrome update (Windows, run as admin):
& "C:\Program Files\Google\Chrome\Application\chrome.exe" --update

# Verify via Chrome UI:
# chrome://settings/help → "Google Chrome is up to date"

# Enterprise deployment (WSUS/Intune/GPO):
# Deploy Chrome 149.0.7827.102+ MSI via your standard endpoint management tool
# Force update policy: Set ExtensionInstallForcelist and update deadline

# Linux (Debian/Ubuntu):
apt-get update && apt-get install --only-upgrade google-chrome-stable

# Linux (RHEL/Fedora):
dnf update google-chrome-stable

# macOS:
# Drag-and-drop update from chrome://settings/help or via Homebrew:
brew upgrade --cask google-chrome

# Microsoft Edge (Chromium-based) — typically patches within 48h:
winget upgrade Microsoft.Edge

This is the fifth Chrome zero-day patched in 2026 following CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, and CVE-2026-5281. Browser patching cadence should be treated as a continuous process, not a monthly task.


Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther