
# CVE-2026-11645 - Chrome V8 Out-of-Bounds Read/Write Exploit
This code is ONLY for educational purposes and authorized testing.
CVE-2026-11645 is an out-of-bounds read and write (OOB) vulnerability in the V8 engine of Google Chrome. A remote attacker can execute arbitrary code within the sandbox via a manipulated HTML page.
| Field | Value |
|---|---|
| CVE | CVE-2026-11645 |
| CVSS | 8.8 (High) |
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| Component | V8 JavaScript Engine |
| Type | CWE-125 (OOB Read), CWE-787 (OOB Write) |
| Product | Vulnerable Versions |
|---|---|
| Google Chrome | < 149.0.7827.103 |
| Microsoft Edge | < 149.0.7827.103 |
| Opera | < 149.0.7827.103 |
| Any Chromium-based browser | < 149.0.7827.103 |
# Start local server
python3 -m http.server 8080
# Access from vulnerable browser
# http://localhost:8080/index.html
| Phase | Description |
|---|---|
| 1 | Memory preparation (ArrayBuffers, objects) |
| 2 | JIT compilation training |
| 3 | OOB read for memory leak |
| 4 | OOB write for memory corruption |
| 5 | Type confusion for RCE |
Update Chrome to version 149.0.7827.103 or later.
# Windows
chrome://settings/help
# Linux
sudo apt update && sudo apt upgrade chromium-browser
# macOS
# Update from Chrome menu > About Google Chrome
text
| Phase | Relevant Code | Purpose |
|---|---|---|
| 1 | victimBuffer = new ArrayBuffer(0x100) | Memory setup |
| 2 | function vulnerableFunction(arr, idx, val) | Vulnerable function |
| 3 | Loop for (let i = 0; i < 10000; i++) | Train JIT |
| 4 | %OptimizeFunctionOnNextCall | Force optimization |
| 5 | oobIndex = 5 + attempt | Trigger OOB |
| 6 | vulnerableFunction(oobArray, writeIndex, targetValue) | OOB write |
| 7 | confusingFunction(buffer1, buffer2, 0x80) | Type confusion |
| 8 | typeCorruption(uintArray, 19, 0xdeadbeef) | Memory corruption |
Do you need me to elaborate on any specific phase or generate more PoC components?