A critical vulnerability in Google Chrome and all Chromium-based browsers is being actively exploited in the wild. CISA added this to its Known Exploited Vulnerabilities catalog on 9 June 2026, signalling that real attacks are underway.
- What it is: CVE-2026-11645 is an out-of-bounds read and write flaw in Chrome's V8 JavaScript engine. An attacker can exploit it through a malicious web page — no download required.
- Who is affected: Anyone using Google Chrome, Microsoft Edge, Opera, Brave, or any other Chromium-based browser that has not been updated recently.
- What the risk is: A successful attack could allow remote code execution, meaning an attacker could take control of the affected computer simply by directing a user to a crafted web page.
- What to do: Update Chrome, Edge, and any other Chromium-based browsers immediately. In Chrome, go to Help > About Google Chrome to check for and apply updates. Restart the browser after updating.
We recommend businesses ensure browser updates are applied across all staff devices today. For organisations that manage browsers centrally, confirm the latest version is deployed. Source: CISA KEV Catalog.