Google addresses exploitation of Chrome RCE vulnerability

Google has released a new version of Chrome containing 74 security fixes. One of them, CVE-2026-11645 with a CVSS score of 8.8, has a known exploit in the wild according to Google. The vulnerability is a high-severity out-of-bounds read/write issue in the V8 engine that enables a remote attacker to execute arbitrary code inside the browser sandbox. It also grants access to memory beyond the allotted buffer, potentially leaking sensitive information.

What this means for your organisation

The browser is the working surface for most employees, and an attack that starts there reaches everything from email to cloud business systems. When exploitation is already under way, waiting for machines to update at the user's convenience is not sufficient. Organisations without visibility into which Chrome versions are actually running also lack the answer to whether they are exposed.

Berigo recommends

  • Push the Chrome update centrally and require a browser restart so the fix actually takes effect.
  • Establish reporting on browser version per device so the backlog is measurable rather than assumed.
  • Set an internal deadline for deploying fixes with known exploitation, considerably shorter than for ordinary updates.
  • Restrict browser extensions to an approved list to reduce the attack surface around the engine itself.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch