Google patches actively exploited Chrome zero‑day vulnerability
Google has issued a security update for the Chrome browser, moving the stable channel to version 149.0.7827.102/103 for Windows and macOS and 149.0.7827.102 for Linux. The update fixes 74 vulnerabilities, most notably CVE‑2026‑11645 – an out‑of‑bounds read and write flaw in Chrome’s V8 JavaScript and WebAssembly engine that is being actively exploited in the wild. The bug could allow a remote attacker to execute arbitrary code inside Chrome’s sandbox via a crafted HTML page.
Users are advised to install the update promptly and restart the browser. The patch also applies to other Chromium‑based browsers such as Microsoft Edge, Brave, Opera and Vivaldi, which should track their vendors for corresponding releases. The rapid response highlights the importance of timely browser patching for both personal and enterprise security.