Particle.news

Google Issues Emergency Chrome Update to Fix 74 Vulnerabilities Including Exploited V8 Zero‑Day

A working exploit that can run code or read browser memory makes immediate updates urgent.

Overview

  • Google released out‑of‑cycle Chrome builds this week (Windows 149.0.7827.102, macOS 149.0.7827.103, Linux 149.0.7827.102) that patch 74 security flaws and close the zero‑day CVE‑2026‑11645.
  • CVE‑2026‑11645 is an out‑of‑bounds memory access in Chrome’s V8 JavaScript engine that can be triggered by crafted web pages to read or write memory, crash the browser, or allow arbitrary code execution.
  • Google says it found 71 of the 74 bugs internally, paid a $55,000 bounty for the reported zero‑day, and is withholding technical details until most users receive the update to avoid guiding attackers.
  • Brave and Microsoft Edge have already rolled in the Chromium fix while other Chromium‑based browsers are at varying patch levels, and Google warns automatic updates may take days or weeks so users should check Chrome’s About page or restart the browser to force the update.
  • This is the fifth actively exploited Chrome zero‑day reported this year, a pattern that raises the risk of fast follow‑on attacks and underlines why keeping browsers on automatic updates is crucial for user security.