PT-2026-47471 · Google · Google Chrome+1
CVE-2026-11645
·
Published
2026-06-08
·
Updated
2026-07-23
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 149.0.7827.103
Description
An out-of-bounds read and write issue exists in V8, the JavaScript and WebAssembly engine used by Google Chrome. This flaw allows a remote attacker to execute arbitrary code within the browser sandbox by enticing a user to visit a specially crafted HTML page. The issue has been actively exploited in the wild and can be used to bypass security mechanisms such as ASLR (Address Space Layout Randomization), which is a technique used to prevent the execution of arbitrary code by randomizing the memory addresses used by system processes.
Recommendations
Update Google Chrome to version 149.0.7827.103 or later and fully restart the browser to activate the patch.
Fix
LPE
RCE
DoS
Memory Corruption
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Google Chrome
V8