Google patches new Chrome zero-day flaw exploited in the wild
Google has released a security update to address a newly discovered and actively exploited zero-day vulnerability (CVE-2026-11645) within the Chrome browser. This flaw, originating in the V8 JavaScript engine, allows attackers to execute arbitrary code within the browser's sandbox, potentially leading to data breaches and system crashes. Google’s Threat Analysis Group has been actively tracking and mitigating these vulnerabilities, highlighting the ongoing need for vigilance in the face of rapidly evolving threats.
The vulnerability, classified as high severity, stems from an out-of-bounds read and write weakness in Chrome’s V8 engine. Attackers can leverage crafted HTML pages to exploit this flaw, gaining unauthorized access to memory beyond allocated buffers and potentially triggering crashes. Furthermore, the vulnerability could bypass security measures like ASLR, simplifying code execution. Google’s response demonstrates a proactive approach to patching critical vulnerabilities, but also underscores the speed at which these exploits can be deployed and utilized. The company’s Threat Analysis Group (TAG) continues to play a vital role in identifying and tracking these zero-day exploits, often before they are widely publicized.