CVE-2026-11645: Chrome V8 Zero-Day — OOB Read/Write In-Browser RCE Analysis
Technical analysis of the Chrome V8 out-of-bounds read/write memory corruption zero-day exploited in targeted surveillance campaigns.
CVE-2026-11645
Severity: CVSS 8.8
Status: ⚠️ Actively Exploited Browser In-The-Wild Zero-Day
Target Component: Google Chrome V8 Engine
This post is part of the Week of June 12, 2026 Security Roundup.
Vulnerability Overview
CVE-2026-11645 is an out-of-bounds read and write vulnerability in Chrome's V8 JavaScript/WebAssembly engine, rated CVSS 8.8 High. Google confirmed active exploitation in the wild prior to patching. CISA added it to the Known Exploited Vulnerabilities catalog on June 9, 2026, with FCEB agencies required to remediate by June 23.
CVE: CVE-2026-11645
CVSS v3.1: 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CWE: CWE-787 (Out-of-bounds Write) / CWE-125 (Out-of-bounds Read)
Component: V8 JavaScript/WebAssembly engine
Fixed in: Chrome 149.0.7827.102/.103 (Windows/macOS), 149.0.7827.102 (Linux)
Patch date: June 8, 2026
CISA KEV: June 9, 2026 | Remediation deadline: June 23, 2026
Technical Analysis
V8's JIT compiler performs aggressive optimizations including type specialization and bounds-check elimination. When a crafted JavaScript pattern tricks V8's optimizer into eliminating a bounds check on a typed array operation, subsequent reads and writes can occur outside the intended buffer boundaries in the V8 heap. The OOB access can be leveraged to corrupt adjacent objects in V8's managed heap, enabling:
- Type confusion between V8 object types
- Arbitrary read from V8 heap memory (disclosure of pointers, secrets)
- Controlled write to V8 heap (overwrite function pointers, JIT stubs)
- In-renderer RCE within the Chrome renderer sandbox
A full sandbox escape (for OS-level code execution) requires chaining with a second vulnerability—typically a Chrome sandbox escape or a Windows kernel EoP. Active exploitation chains of this type have been observed in spyware and sophisticated threat actor campaigns throughout 2026.
Attack Scenario
1. Attacker hosts or injects a crafted HTML page with malicious JavaScript
2. Victim visits the page (or is served it via malvertising, phishing, or XSS)
3. CVE-2026-11645 triggers OOB write in V8 → in-renderer code execution
4. [Optional] Sandbox escape via second vulnerability → OS-level compromise
5. Payload delivery: credential stealer, RAT, cryptominer, ransomware dropper
Exploitation artifacts to watch for:
- Chrome renderer crashes (check Event Viewer: Application log, source: Application Error)
- Unusual child processes spawned from chrome.exe or chrome --renderer
- Outbound connections from chrome.exe to unexpected IPs
Remediation
# Check current Chrome version
# Windows (PowerShell):
(Get-ItemProperty "HKLM:\SOFTWARE\Google\Chrome\BLBeacon").version
# Target: 149.0.7827.102 or higher
# Force Chrome update (Windows, run as admin):
& "C:\Program Files\Google\Chrome\Application\chrome.exe" --update
# Verify via Chrome UI:
# chrome://settings/help → "Google Chrome is up to date"
# Enterprise deployment (WSUS/Intune/GPO):
# Deploy Chrome 149.0.7827.102+ MSI via your standard endpoint management tool
# Force update policy: Set ExtensionInstallForcelist and update deadline
# Linux (Debian/Ubuntu):
apt-get update && apt-get install --only-upgrade google-chrome-stable
# Linux (RHEL/Fedora):
dnf update google-chrome-stable
# macOS:
# Drag-and-drop update from chrome://settings/help or via Homebrew:
brew upgrade --cask google-chrome
# Microsoft Edge (Chromium-based) — typically patches within 48h:
winget upgrade Microsoft.Edge
This is the fifth Chrome zero-day patched in 2026 following CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, and CVE-2026-5281. Browser patching cadence should be treated as a continuous process, not a monthly task.