Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-11645-Out-of-bounds-Read-Write — # CVE-2026-11645 - Chrome V8 Out-of-Bounds Read/Write Exploit | Kitploit
Tools/GitHubGitHub/fevar54/cve-2026-11645-out-of-bounds-read-write
Vulnerability AnalysisExploitationWeb Application ExploitationCTFLearning & EducationBinary Exploitation
GitHubfevar54/cve-2026-11645-out-of-bounds-read-write

CVE-2026-11645-Out-of-bounds-Read-Write

# CVE-2026-11645 - Chrome V8 Out-of-Bounds Read/Write Exploit

View Repository
34133 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-11645 - Chrome V8 Out-of-Bounds Read/Write Exploit

Security Rating CVSS CISA KEV

⚠️ WARNING

This code is ONLY for educational purposes and authorized testing.

📋 Description

CVE-2026-11645 is an out-of-bounds read and write (OOB) vulnerability in the V8 engine of Google Chrome. A remote attacker can execute arbitrary code within the sandbox via a manipulated HTML page.

Technical Details

FieldValue
CVECVE-2026-11645
CVSS8.8 (High)
VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
ComponentV8 JavaScript Engine
TypeCWE-125 (OOB Read), CWE-787 (OOB Write)

🎯 Affected Versions

ProductVulnerable Versions
Google Chrome< 149.0.7827.103
Microsoft Edge< 149.0.7827.103
Opera< 149.0.7827.103
Any Chromium-based browser< 149.0.7827.103

🚀 Usage

# Start local server
python3 -m http.server 8080

# Access from vulnerable browser
# http://localhost:8080/index.html

🔧 Exploit Phases

PhaseDescription
1Memory preparation (ArrayBuffers, objects)
2JIT compilation training
3OOB read for memory leak
4OOB write for memory corruption
5Type confusion for RCE

🛡️ Mitigation

Update Chrome to version 149.0.7827.103 or later.

# Windows
chrome://settings/help

# Linux
sudo apt update && sudo apt upgrade chromium-browser

# macOS
# Update from Chrome menu > About Google Chrome

📚 References

  • NVD - CVE-2026-11645
  • Chrome Release
  • CISA KEV
  • Chromium Issue 506689381

text


📝 Analysis Summary

PhaseRelevant CodePurpose
1victimBuffer = new ArrayBuffer(0x100)Memory setup
2function vulnerableFunction(arr, idx, val)Vulnerable function
3Loop for (let i = 0; i < 10000; i++)Train JIT
4%OptimizeFunctionOnNextCallForce optimization
5oobIndex = 5 + attemptTrigger OOB
6vulnerableFunction(oobArray, writeIndex, targetValue)OOB write
7confusingFunction(buffer1, buffer2, 0x80)Type confusion
8typeCorruption(uintArray, 19, 0xdeadbeef)Memory corruption

Do you need me to elaborate on any specific phase or generate more PoC components?

Download Tool