The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Google Chromium V8 vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, warning that the flaw is being actively exploited in the wild.
Tracked as CVE-2026-11645, the zero-day affects the V8 JavaScript and WebAssembly engine embedded in Chromium-based browsers and poses a significant risk to both enterprise and consumer environments.
CVE-2026-11645 is an out-of-bounds read and write vulnerability in Google Chromium’s V8 engine, classified under CWE-787 (Out-of-Bounds Write) and CWE-125 (Out-of-Bounds Read).
Google Chromium 0-Day Flaw Exploited
The flaw enables a remote attacker to execute arbitrary code within a sandbox environment by tricking a victim into visiting a specially crafted HTML page requiring no user interaction beyond a single browser visit.
Because the vulnerability resides in the Chromium engine itself, its impact extends well beyond Google Chrome, CISA said.
Any browser built on the Chromium codebase, including Microsoft Edge, Opera, Brave, and Vivaldi, is potentially affected, dramatically widening the attack surface.
CISA added CVE-2026-11645 to the KEV catalog on June 9, 2026, confirming active exploitation in real-world attacks.
Federal Civilian Executive Branch (FCEB) agencies are required to remediate the vulnerability by June 23, 2026, in accordance with Binding Operational Directive (BOD) 22-01.
While CISA has not yet confirmed direct ties to ransomware campaigns, the agency lists ransomware association as “Unknown,” meaning that the connection cannot be ruled out.
Given that browser-based zero-days are a favored initial access vector for ransomware operators and espionage-linked threat actors alike, organizations should treat this with the highest urgency.
Mitigation
CISA recommends the following immediate actions:
- Apply vendor patches as soon as they become available from Google, Microsoft, Opera, and other affected browser vendors
- Follow BOD 22-01 guidance for any cloud-hosted services that incorporate Chromium-based rendering engines
- Discontinue use of affected browser products if patches cannot be applied within the remediation window
- Monitor browser telemetry for anomalous JavaScript execution or unexpected process spawning from browser processes
Out-of-bounds memory vulnerabilities in JavaScript engines are particularly dangerous because they can be chained with sandbox-escape exploits to achieve a full system compromise.
Organizations are strongly advised to enforce rapid patch deployment policies for all Chromium-based browsers across managed endpoints and to prioritize browser security hygiene as a frontline defense.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.