🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.
Chrome V8 Out-of-Bounds Memory Access RCE (CVE-2026-11645) | MSSP Advisory
Critical🔴 KEV ALERTConfirmed
DateJune 9, 2026
CVECVE-2026-11645
CVSS Score8.8
Affectedchrome, macos, linux_kernel
Risk Assessment
Client Exposure:High
Briefing Priority:Immediate
Barrier to Entry:Low
📋Executive Summary
Google has patched CVE-2026-11645, an out-of-bounds memory access flaw in the V8 JavaScript engine affecting Chrome versions prior to 149.0.7827.103, and has confirmed active exploitation in the wild. A remote attacker can execute arbitrary code inside the Chrome sandbox by directing a target to a crafted HTML page, requiring no user interaction beyond visiting the page. This is the fifth actively exploited Chrome zero-day patched by Google so far in 2026, which tells you the targeting cadence on browser-based entry points is not slowing down.
⚠️Why It Matters for MSSPs
Every technician on your team is running Chrome or a Chromium-based browser while logged into your RMM, PSA, and client portals, which means a single malicious page visit can hand an attacker a foothold inside the same browser session that holds your client credentials and remote access tokens. On the client side, your managed endpoints are almost certainly running unpatched Chrome right now, and if one of those users gets hit before you push the update, you own that conversation about why you did not act faster. This is not a theoretical risk, Google has confirmed exploitation is already happening.
✅Recommended Action
Push Chrome version 149.0.7827.102 or 149.0.7827.103 to every managed endpoint and every internal technician workstation within the next 24 hours using your RMM, and send a direct client notification today naming CVE-2026-11645 and confirming the patch is in flight.
🔒Get your first advisory free →
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
🏷️Threat Category
Zero-Day
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.