Google released an urgent Chrome desktop update to fix 74 security issues, including CVE-2026-11645, a high-severity out-of-bounds memory access vulnerability in the V8 JavaScript engine. Google said an exploit for the flaw exists in the wild, making it the most pressing issue in the release. The update affects Chrome on Windows, macOS, and Linux, and Google limited technical details for some bugs until more users receive the patch.
The release also addresses multiple additional memory-safety flaws, including use-after-free bugs in components such as Ozone, Bluetooth, and tab strips. HKCERT separately published an advisory covering multiple Chrome vulnerabilities, reinforcing the breadth of the fixes. Organizations are being urged to update Chrome immediately and ensure browser restarts are completed so the patched version is applied across managed endpoints.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CISA added CVE-2026-11645 to its Known Exploited Vulnerabilities catalog on 2026-06-09, warning that the Chromium V8 flaw is being actively exploited. Under Binding Operational Directive 22-01, federal agencies were ordered to remediate the issue by 2026-06-23.
Google released an urgent Chrome desktop security update addressing CVE-2026-11645, a high-severity out-of-bounds memory access vulnerability in the V8 JavaScript engine. Google said an exploit for the flaw exists in the wild and noted the update also includes 74 security fixes affecting Windows, macOS, and Linux desktop platforms.
Google said researcher "303f06e3" reported CVE-2026-11645, an out-of-bounds memory access flaw in the V8 engine, on 2026-04-27. The company awarded a $55,000 bug bounty for the finding.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
20 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceblog.alyac.co.kr
Open sourcelinuxsecurity.com
Open sourcexakep.ru
Open sourcetheregister.com
Open sourcechromereleases.googleblog.com
Open sourcecvereports.com
Open sourceopennet.ru
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.