V8 npm Package Vulnerability CVE-2026-11645: Update Chrome Now
The V8 npm package, Chrome's JavaScript and WebAssembly engine, has a high-severity vulnerability tracked as CVE-2026-11645 that is being actively exploited. Users of Chrome and other Chromium-based browsers are affected.
What happened
The V8 npm package, which is Chrome's JavaScript and WebAssembly engine, has a high-severity vulnerability tracked as CVE-2026-11645. This vulnerability is an out-of-bounds memory access that allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. Google has confirmed that an exploit for this vulnerability exists in the wild. To mitigate the risk, users are advised to update their Chrome browser to versions 149.0.7827.102/.103 for Windows and Apple macOS, and 149.0.7827.102 for Linux. Users of other Chromium-based browsers, such as Microsoft Edge, Brave, Opera, and Vivaldi, should also ensure they are running the latest versions.
How 0Day mitigates this
v8 is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.