Skip to content
COOEY

EXPOSURES › CVE-2026-11645

CVE-2026-11645

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-06-09 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-11645 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 rceexploited-in-wildransomwaresupply-chain

Google Chromium V8 allows remote code execution via crafted HTML pages, enabling sandbox escape and arbitrary code execution.

This vulnerability allows remote attackers to execute arbitrary code inside the browser sandbox via crafted HTML pages, posing a significant risk to DIB organizations relying on Chromium-based browsers for sensitive data handling. The active exploitation status and potential for sandbox escape mean vendors must prioritize patching and users should verify browser integrity to prevent unauthorized access to classified or sensitive information.

Shame score — Active exploitation of a remote code execution vulnerability in a widely used browser engine indicates a critical security oversight.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized