PT-2026-47471 · Google · V8+1
Published
2026-06-08
·
Updated
2026-06-11
·
CVE-2026-11645
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 149.0.7827.103
Description
An out-of-bounds read and write issue exists in V8, the JavaScript engine used by Google Chrome. This flaw allows a remote attacker to execute arbitrary code inside the browser sandbox by enticing a user to visit a specially crafted HTML page. The issue can also be used to bypass security mechanisms such as ASLR (Address Space Layout Randomization), which is a technique used to prevent exploitation by randomly arranging the address space positions of key data areas of a process. This flaw has been actively exploited in the wild.
Recommendations
Update Google Chrome to version 149.0.7827.103 or later. After installing the update, fully restart the browser to activate the patched version.
Fix
RCE
Out of bounds Read
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Google Chrome
V8