Google has patched CVE-2026-11645, an actively exploited flaw in Chrome’s V8 JavaScript and WebAssembly engine that can give attackers both out-of-bounds read and write capabilities from a crafted web page. The bug affects Chrome prior to 149.0.7827.103 on Windows and macOS and 149.0.7827.102 on Linux, creating a realistic drive-by compromise path in which renderer-process code execution could be chained with a sandbox escape for full device takeover. Public reporting notes that Google confirmed in-the-wild exploitation but did not disclose the campaign, attribution, or full exploit chain.
The risk is amplified across the broader Chromium ecosystem because many Electron and Chromium-based applications ship their own embedded V8 runtimes and may remain vulnerable after browser updates. Historical Chromium issues and research around XSS Auditor and Chrome security bugs—including bypasses, cross-origin data extraction, form-data leakage through redirects, and Egor Homakov’s account of abusing Chrome bugs in an OAuth flow—underscore how browser flaws can expose sensitive data or be combined into larger attack chains. Organizations are being pushed to update Chrome immediately and inventory Chromium-derived applications that may require separate patch cycles.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
CISA added CVE-2026-11645, a Chrome V8 out-of-bounds read/write vulnerability, to its Known Exploited Vulnerabilities catalog after active exploitation was confirmed. The reference states the KEV addition occurred on this date.
A Chromium security issue documented that the body of a POST request in a 302 redirect chain could be recovered by script on the final page using XSS Auditor. This expanded public reporting on data leakage risks tied to the feature.
A Chromium security issue reported that XSS Auditor behavior could leak submitted form data through an about:blank redirection flow. The issue described exposure of POSTed information caused by browser handling of redirects.
A Chromium issue documented that universal cross-site scripting could be performed because XSS Auditor processed tokens inside script tags separately. The report described a flaw that could enable broader script injection impact.
Egor Homakov published a blog post titled "How we hacked Facebook with OAuth2 and Chrome bugs." The post publicly tied Chrome XSS Auditor-related flaws to a real attack scenario involving Facebook OAuth2.
A Chromium issue was published describing data extraction made possible through XSS Auditor behavior. The report showed that the protection mechanism itself could be abused to leak information.
A Chromium security issue reported an XSSAuditor bypass using a leading comment pattern `/*///*/`. The report documented another technique for defeating the browser's XSS filtering logic.
A Chromium security issue documenting an XSS Auditor bypass using SVG tags was published. This indicates an early reported weakness in Chrome's XSS Auditor protections.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
codeby.net
Open sourcecode.google.com
Open sourcecode.google.com
Open sourcecode.google.com
Open sourcehomakov.blogspot.jp
Open sourcecode.google.com
Open sourcecode.google.com
Open sourcecode.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.