Buffer overflow in Google Chromium - CVE-2026-11645

 

Buffer overflow in Google Chromium - CVE-2026-11645

Published: June 9, 2026


Vulnerability identifier: #VU133930
CSH Severity: Critical
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-11645
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a boundary error in V8 engine in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger a stack-based buffer overflow and execute arbitrary code on the system.

Note, the vulnerability is being actively exploited in the wild.


Affected software

Google Chromium
Microsoft Edge
Google Chrome
Debian Linux
Fedora
chromium
chromium (Debian package)

How to mitigate CVE-2026-11645

Install update from vendor's website.

Google Chromium - update to 149.0.7827.102
Microsoft Edge - update to 149.0.4022.62
Google Chrome - update to 149.0.7827.102
chromium - addressed in versions 149.0.7827.102-1.el9, 149.0.7827.102-1.el10_2, 149.0.7827.102-1.el10_3, 149.0.7827.102-1.fc43, 149.0.7827.102-1.fc44
chromium (Debian package) - addressed in versions 149.0.7827.102-1~deb12u1, 149.0.7827.102-1~deb13u1

External References

Related Security Bulletins