Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
https://www.securityweek.com/no-patch-planned-for-exploited-arista-eos-vulnerability/
https://thehackernews.com/2026/06/cisa-adds-cisco-chrome-and-arista-flaws.html
https://www.securityweek.com/google-patches-5th-chrome-zero-day-exploited-in-2026/
https://www.infosecurity-magazine.com/news/google-patch-chrome-vulnerability/
https://www.helpnetsecurity.com/2026/06/09/google-chrome-zero-day-cve-2026-11645/
https://thehackernews.com/2026/06/chrome-v8-zero-day-cve-2026-11645.html
https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html