Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now
Google has released an emergency security update for its Chrome browser, patching 74 vulnerabilities, including a high-severity zero-day exploit (CVE-2026-11645) that is actively being exploited in the wild. The vulnerability, which carries a CVSS score indicating significant risk, affects the V8 JavaScript engine and could allow remote code execution. Google confirmed that an exploit exists and urged all users to update immediately. The update is rolling out globally across Windows, macOS, and Linux platforms. This marks the first confirmed zero-day for Chrome in 2026, following a trend of increasing browser-based attacks targeting enterprise and consumer systems alike. Security researchers have linked the exploit to a known advanced persistent threat (APT) group, though attribution remains unconfirmed. Organizations using Chromium-based browsers (Edge, Brave, Opera) are also advised to patch as they inherit the same vulnerability.
Global Impact
This zero-day exploit has immediate economic and technological consequences. Economically, enterprises face direct costs from incident response, forensic analysis, and potential data breach remediation, with estimates ranging from $500K to $5M per affected organization.
Sources on this story
Reported by 1 sources, including:
- The Hacker News