North America
Google Chrome
On June 8, Google released emergency security updates to patch another Chrome zero-day vulnerability that is being actively exploited in the wild. The flaw is the fifth Chrome zero-day vulnerability patched by Google since the start of 2026.
The high-severity vulnerability, tracked as CVE-2026-11645, stems from an out-of-bounds read and write weakness in Chrome’s V8 JavaScript engine. Attackers can exploit the flaw through specially crafted HTML pages to execute arbitrary code within the browser’s sandbox. Successful exploitation can lead to heap corruption, allowing attackers to access data outside the memory buffer, expose sensitive information or trigger browser crashes. The vulnerability could also be used to bypass security protections such as Address Space Layout Randomization (ASLR), making it easier to achieve code execution through additional flaws.
While Google has warned that it may take days or even weeks for the security update to reach all Chrome users automatically, the patch is now available for installation.
How it could affect your business
Running an unpatched version of Google Chrome can expose users and organizations to significant security risks, particularly when vulnerabilities are already being actively exploited in the wild. Organizations should ensure browsers are updated as quickly as possible to reduce the risk of compromise. Users who prefer not to manually update Chrome can rely on the browser’s built-in update mechanism, which automatically checks for and installs available security updates the next time the browser is launched.
