← Back to browse · API

CVE-2026-11645

Severity
HIGH
CVSS
8.8
EPSS
0.0219
Risk score
60.97
CISA KEV
Yes
PoC
No
Published
2026-06-08
Modified
2026-06-10
First seen
2026-08-05
Aliases
EUVD-2026-35245, GHSA-X2HH-W9MW-3VQ2
Products
Google:Chrome 149.0.7827.103 <149.0.7827.103, Google:Chromium V8, apple:macos, google:chrome, linux:linux_kernel, microsoft:windows
Sources
nvd CVE-2026-11645
cisa.gov CVE-2026-11645
euvd EUVD-2026-35245

Description

Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

References