Google has issued an emergency security update for its Chrome web browser to address a high-severity zero-day vulnerability tracked as CVE-2026-11645. The flaw, an out-of-bounds memory access issue in the V8 JavaScript engine, is confirmed to be actively exploited in the wild. Successful exploitation allows a remote attacker to execute arbitrary code within the browser's sandbox by persuading a user to visit a malicious website. This marks the fifth Chrome zero-day patch released in 2026, highlighting a persistent trend of attackers targeting browser vulnerabilities. All Chrome users on Windows, macOS, and Linux are strongly advised to update to the latest version immediately to protect against ongoing attacks.
CVE-2026-11645 is classified as an out-of-bounds memory access vulnerability within V8, Chrome's open-source JavaScript and WebAssembly engine. This type of flaw allows an attacker to read or write to memory outside of the intended buffer. By crafting a malicious HTML page with specific JavaScript code, an attacker can trigger this condition.
Exploitation can lead to heap corruption, which can be leveraged to bypass security mechanisms and achieve arbitrary code execution within the context of the browser's sandboxed renderer process. While the sandbox provides a layer of protection, attackers often chain such exploits with a second vulnerability (a sandbox escape) to gain full control over the underlying system.
Google has explicitly stated, "Google is aware that an exploit for CVE-2026-11645 exists in the wild." This confirms that threat actors are actively using this vulnerability in real-world attacks. As is typical, Google has not released technical details about the exploit or the identity of the attackers to prevent wider abuse and give users time to patch. The vulnerability was responsibly disclosed by a researcher on April 27, 2026.
This is the fifth Chrome zero-day patched in 2026, indicating a sustained focus by threat actors on browser-based exploits for initial access and malware delivery.
A successful exploit of CVE-2026-11645 could allow an attacker to execute arbitrary code on a victim's machine. This could be used to:
Given that the web browser is a primary interface to the internet for most users, a vulnerability like this has a massive potential attack surface, affecting millions of individuals and organizations worldwide.
No specific Indicators of Compromise (IPs, domains, hashes) were provided in the source articles.
The following patterns may help identify systems at risk or potential exploitation activity:
chrome.exe < 149.0.7827.103chrome.exechrome.exe processes spawning suspicious child processes (e.g., powershell.exe, cmd.exe) which could indicate a successful sandbox escape.Detection focuses on identifying vulnerable software and anomalous browser behavior.
chrome.exe spawns a command shell or other unexpected processes. This can be achieved via D3-PA: Process Analysis.Patching is the primary and most effective mitigation.
Help > About Google Chrome.CISA has added the actively exploited Chrome zero-day (CVE-2026-11645) to its KEV catalog, mandating federal agencies to patch by July 1, 2026, highlighting increased urgency.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially recognized the active exploitation of CVE-2026-11645, the Google Chrome V8 zero-day, by adding it to its Known Exploited Vulnerabilities (KEV) catalog. This inclusion mandates all U.S. Federal Civilian Executive Branch agencies to apply patches for this vulnerability by July 1, 2026. This development significantly elevates the urgency and priority for all organizations, not just federal ones, to remediate this flaw immediately due to confirmed ongoing attacks and its critical impact potential. The KEV listing serves as a clear signal of the severe and present danger posed by this vulnerability.
Google's urgent Chrome update patches 28 vulnerabilities, including the actively exploited CVE-2026-11645, now confirmed as a drive-by compromise attack vector.
The latest Chrome update, version 149, addresses a total of 28 vulnerabilities, significantly expanding beyond the previously reported CVE-2026-11645. Google has now confirmed that CVE-2026-11645 is being actively exploited via 'drive-by compromise' attacks, where users are compromised simply by visiting a malicious website. This type of zero-day is highly valued by sophisticated threat actors, including state-sponsored APT groups like APT28 and APT29, as well as cybercriminal organizations. Enhanced detection methods, such as monitoring EDR alerts for suspicious process creation from chrome.exe and network traffic analysis for unusual C2 communications, are now emphasized.
CVE-2026-11645 was responsibly disclosed to Google.
Google releases an emergency security update for Chrome to patch CVE-2026-11645.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.