
CVE-2026-11645
⚠️ CVE-2026-11645 is a high-severity zero-day vulnerability affecting the Google Chrome V8 JavaScript engine. The flaw allows attackers to trigger an Out-of-Bounds Read/Write condition that may lead to Remote Code Execution (RCE).
The vulnerability exists within Chrome's V8 JavaScript engine.
An attacker can craft a malicious webpage that:
🌐 Victim Opens Malicious Website
│
▼
📜 Crafted JavaScript Payload
│
▼
🧩 V8 Engine Vulnerability Triggered
│
▼
💥 Out-of-Bounds Memory Access
│
▼
⚡ Remote Code Execution
│
▼
🚨 Browser Compromise
Chrome < 149.0.7827.103
🪟 Windows : 149.0.7827.102+
🍎 macOS : 149.0.7827.103+
🐧 Linux : 149.0.7827.102+
| Impact | Risk |
|---|---|
| ⚡ Remote Code Execution | 🔴 High |
| 🔍 Information Disclosure | 🔴 High |
| 💣 Browser Crash | 🟠 Medium |
Monitor for:
🚨 Indicators:
- Unexpected browser crashes
- Suspicious JavaScript activity
- Exploit-kit traffic
- Malicious domain visits
- Unusual Chrome child processes
- Browser memory anomalies
chrome://settings/help
Likelihood : ██████████ HIGH
Impact : ██████████ HIGH
Overall : 🚨 CRITICAL 🚨
This repository is provided for:
❌ No exploit code is included.
| 🏷️ Field | 📋 Value |
|---|
| CVE | CVE-2026-11645 |
| 🔥 Severity | High |
| 📊 CVSS | 8.8 |
| 🏢 Vendor | |
| 🌐 Product | Chrome |
| 🧩 Component | V8 Engine |
| 💥 Type | Out-of-Bounds Read/Write |
| ⚠️ Exploited | Yes |
| 🎯 Impact | Remote Code Execution |
| 🔗 Exploit Chaining |
| 🟠 Medium |
| 🏢 Enterprise Risk | 🔴 High |