Google has shipped an emergency Chrome update to fix a security hole that hackers are already using to attack people. If you have not restarted Chrome in the last few days, you should do it right now. The patch went out on June 8, 2026, in the Stable channel, and it closes a flaw that Google confirms is being exploited in the wild.
The bug, tracked as CVE-2026-11645, sits in V8, the part of Chrome that runs JavaScript on web pages. According to the official Chrome Releases blog, the update fixes 74 security issues in total, and this one is rated high severity. A booby-trapped web page can trigger it, which means simply visiting the wrong site could be enough to put you at risk.
In plain terms, the flaw lets a remote attacker run their own code inside Chrome’s protective sandbox. The sandbox is a sealed-off area meant to keep bad code boxed in, so this is not the same as someone taking over your whole computer. But it is still serious, because that boxed-in space can hold your logged-in sessions, the data on the page you are viewing, and your saved browsing activity. Attackers also often pair a bug like this with a second one to break out of the sandbox entirely.
This is the fifth Chrome zero-day Google has patched in 2026. As is standard practice, Google is holding back the deeper technical details until most people have installed the fix, so attackers cannot use that information to target users who have not updated yet. A researcher reported the flaw in late April and earned a reward for the disclosure.
Here is the part that trips people up: Chrome usually updates itself in the background, but the fix does not actually take effect until you close and reopen the browser. If you keep Chrome running for days at a time with dozens of tabs open, you could still be exposed even though the update has technically downloaded.
To update right now, click the three-dot menu in the top-right corner, then go to Help > About Google Chrome. Chrome will check for the update and download it automatically. When it finishes, click Relaunch to restart the browser and lock in the fix. You want to be on version 149.0.7827.103 (or 149.0.7827.102 on Linux) or newer.
If you use another Chromium-based browser like Microsoft Edge, Brave, Opera, or Vivaldi, watch for their updates too. They share the same underlying engine, so they need their own patches, which often arrive a little later.

Leave a Reply