Critical Analysis: CVE-2026-11645 - Google Chromium V8 Out-of-Bounds Read and Write Vulnerabilit... — June 12, 2026
Published 12 Jun 2026 · vulnerability management, CVE analysis, threat intelligence, security operations, cybersecurity news
Initial Discovery and Context Alright team, let's cut straight to the chase on CVE-2026-11645. This one dropped today, June 12, 2026, and it's a doozy: a critical Out-of-Bounds (OOB) Read and Write vulnerability in Google's V8 JavaScript engine. We're talking CVSSv3.1 score of 9.8, the kind of criticality that makes our CTI team's hair stand on end. Initial reports, primarily from Project Zero and some independent researchers, indicate this gem was found in the wild, which always ratchets up the urgency. Specifically, it affects V8 versions prior to 12.6.280.12. This means any Chromium-based browser—Chrome, Edge, Brave, Opera—and any application embedding V8, like Electron, Node.js, and even certain IoT device firmwares, are potentially vulnerable. It’s a widespread architectural dependency, hitting a core component responsible for executing arbitrary JavaScript. Think about the attack s