VORANT. Threat Intelligence Sign in Get the full feed

CVE-2026-11645 exploited in Chrome zero-day

high vulnerability

Google patched 74 vulnerabilities in Chrome, including CVE-2026-11645, which is actively exploited in the wild.

France's CERT has issued an advisory for multiple vulnerabilities discovered in Google Chrome affecting versions prior to 149.0.7827.102 on Linux and Windows, and 149.0.7827.103 on macOS. The advisory covers 74 CVEs ranging from CVE-2026-11628 through CVE-2026-11701. Google has confirmed that CVE-2026-11645 is under active exploitation, elevating the urgency of patching.

The nature of the vulnerabilities has not been detailed by the vendor at this time, which is typical for zero-day disclosures to limit weaponization. Organizations running Chrome should prioritize updating to the patched versions immediately given the confirmed in-the-wild exploitation. The French CERT recommends referring to Google's security bulletin for obtaining the necessary patches.

The sheer volume of fixes in this release—74 CVEs—suggests this may be a bundled security update addressing accumulated issues alongside the actively exploited flaw. Users across all platforms (Linux, Windows, macOS) are affected and should apply updates through Chrome's built-in update mechanism.

Mentioned in this report

Vulnerabilities CVE-2026-11628CVE-2026-11629CVE-2026-11630CVE-2026-11631CVE-2026-11632CVE-2026-11633CVE-2026-11634CVE-2026-11635CVE-2026-11636CVE-2026-11637CVE-2026-11638CVE-2026-11639CVE-2026-11640CVE-2026-11641CVE-2026-11642CVE-2026-11643CVE-2026-11644CVE-2026-11645KEVCVE-2026-11646CVE-2026-11647CVE-2026-11648CVE-2026-11649CVE-2026-11650CVE-2026-11651CVE-2026-11652CVE-2026-11653CVE-2026-11654CVE-2026-11655CVE-2026-11656CVE-2026-11657CVE-2026-11658CVE-2026-11659CVE-2026-11660CVE-2026-11661CVE-2026-11662CVE-2026-11663CVE-2026-11664CVE-2026-11665CVE-2026-11666CVE-2026-11667

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0708

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free