Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
BugHunter: AI-Powered Bug Bounty Toolkit with Claude Free
June 13, 2026
Splunk Enterprise Pre-Auth RCE Chain Exposes Database With Zero
June 13, 2026
Government Directive Blocks Anthropic Fable 5 & Mythos Access
June 13, 2026
Home/CyberSecurity News/Google Chrome 0-Day Exploit: Update Browser Immediately
CyberSecurity News

Google Chrome 0-Day Exploit: Update Browser Immediately

Google has released an emergency security update for its Chrome browser, patching a critical zero-day vulnerability actively exploited in the wild. The Stable channel Here’s the breakdown of the five...

David kimber
David kimber
June 9, 2026 3 Min Read
15 0

Google has released an emergency security update for its Chrome browser, patching a critical zero-day vulnerability actively exploited in the wild. The Stable channel

Table Of Content

  • Google Chrome 0-Day Exploited
  • High-Severity Flaws Across Core Subsystems
  • How to Update Chrome Immediately

Here’s the breakdown of the five actively exploited Chrome zero-days patched in 2026 so far:

CVE Disclosed/Patched Component Vulnerability Type Fixed Version
CVE-2026-2441 Mid-February CSSFontFeatureValuesMap (CSS) Iterator invalidation —
CVE-2026-3909 March (~Mar 12) Skia (2D graphics library) Out-of-bounds write 146.0.7680.75/.76
CVE-2026-3910 March (~Mar 12) V8 (JavaScript/WebAssembly engine) Inappropriate implementation 146.0.7680.75/.76
CVE-2026-5281 Late March (CISA: Apr 1) Dawn (WebGPU implementation) Use-after-free 146.0.7680.177/.178
CVE-2026-11645 June 9 (latest) V8 (JavaScript engine) Out-of-bounds read & write 149.0.7827.102/.103

Google Chrome 0-Day Exploited

The most critical flaw in this update is CVE-2026-11645, a high-severity out-of-bounds memory access vulnerability in Chrome’s V8 JavaScript engine.

Out-of-bounds memory access flaws in V8 are particularly dangerous because the engine processes untrusted JavaScript from every website a user visits.

Successful exploitation can corrupt memory, leak sensitive data, or, when chained with other bugs, lead to remote code execution simply by luring a victim to a malicious page.

Discovered by an external researcher identified as “303f06e3” on April 27, 2026, Google awarded a $55,000 bug bounty for the report, reflecting its significant impact potential.

Google explicitly confirmed: “Google is aware that an exploit for CVE-2026-11645 exists in the wild.” Out-of-bounds memory access flaws in V8 are particularly dangerous because attackers can leverage them to execute arbitrary code within the browser’s renderer process, potentially leading to sandbox escape and full system compromise when chained with other exploits.

The update is far more than a single-bug patch. In total, the release ships 74 security fixes, including 17 Critical vulnerabilities. The overwhelming majority are use-after-free (UAF) defects — a memory-corruption class that remains the most persistent thorn in browser security.

  • Ozone, Aura, and Views (core rendering and UI frameworks)
  • Bluetooth and Gamepad (hardware interface layers)
  • TabStrip, Autofill, and Web Apps (browser feature components)
  • Printing, Compositing, and Proxy
  • libyuv (integer overflow, CVE-2026-11640)

UAF vulnerabilities occur when a program continues using a memory pointer after the referenced memory has been freed. Exploiting these flaws can allow attackers to corrupt memory, execute arbitrary code, or crash the browser entirely.

High-Severity Flaws Across Core Subsystems

The high-severity category includes an additional 57 vulnerabilities affecting nearly every major Chrome subsystem, including V8 (CVE-2026-11649/11650), WebRTC (CVE-2026-11667), PDF (CVE-2026-11670), ServiceWorker (CVE-2026-11656/11694), Extensions (CVE-2026-11652/11653), Network (CVE-2026-11651/11677), and GPU (CVE-2026-11672). The breadth of affected components signals a sweeping internal security audit conducted by Google’s own researchers between late April and late May 2026.

Notably, CVE-2026-11662 introduces a Type Confusion in Bindings, and CVE-2026-11688 flags an Object Lifecycle Issue in SVG — both classes of bugs commonly leveraged in browser exploit chains.

The Stable channel has been updated to 149.0.7827.102/.103 for Windows and Mac, and 149.0.7827.102 for Linux. Google notes the rollout will reach users over the coming days and weeks, so manual updating is strongly recommended rather than waiting for the automatic push.

How to Update Chrome Immediately

Users should not wait for the automatic rollout. To manually update:

  1. Open Chrome and click the three-dot menu (⋮) in the top-right corner
  2. Navigate to Help → About Google Chrome
  3. Chrome will check for updates automatically — click Relaunch once the update downloads

Enterprise administrators should prioritize pushing version 149.0.7827.102/103 across managed endpoints immediately given the confirmed in-the-wild exploitation of CVE-2026-11645.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerabilityzero-day

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Weedhack Malware-as-a-Service Ste Targets Minecraft

Next Post

Fortinet FortiSandbox Vulnerability: Attackers Execute

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Malicious npm Campaign Steals SSH Keys & Cloud Credentials
June 12, 2026
OnyxC2 MaaS Hackers Steal Credentials Malware-as-a-Service From
June 12, 2026
Google Sues Chinese Cybercrime for Gemini AI Cyberattacks
June 12, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us