# Five Chrome Zero-Days in 2026: Why Forgotten Code Is Becoming Your Greatest Security Risk


## The Threat


Google shipped critical security patches for 74 vulnerabilities this week, including CVE-2026-11645, an out-of-bounds memory access in Chrome's V8 JavaScript engine that is already being exploited in the wild. This marks the fifth actively exploited Chrome zero-day since the start of 2026—a grim acceleration that signals attackers are keeping pace with browser security faster than patches can be deployed.


But the Chrome vulnerability tells only part of this week's story. Simultaneously, the ShinyHunters extortion gang (also tracked as UNC6240) was weaponizing CVE-2026-35273, an authentication bypass in Oracle PeopleSoft Enterprise that required zero user interaction. They exploited it to breach over 100 organizations, with 68% being universities and colleges. Meanwhile, hundreds of abandoned packages in the Arch Linux User Repository were silently modified to deploy a sophisticated rootkit and credential harvester called atomic-lockfile, turning the supply chain itself into a vector.


The pattern underlying this week is unmistakable: security failures are no longer concentrated in flashy zero-day discoveries. They're hiding in forgotten code—deprecated features still running in production, unmaintained packages nobody remembers downloading, authentication endpoints left behind during refactors, and infrastructure built years ago and then abandoned. These soft targets are easier to exploit, cheaper to weaponize, and reach organizations at scale because nobody is watching them.


## Severity and Impact


| Vulnerability | Product | CVE | CVSS Score | Vector | Actively Exploited | Key Detail |

|---|---|---|---|---|---|---|

| V8 Out-of-Bounds Memory Access | Google Chrome | CVE-2026-11645 | 8.8 | Network-based, Low Complexity | Yes (in the wild) | Affects all platforms; attackers avoid full disclosure to maximize patch window |

| Missing Authentication | Oracle PeopleSoft Enterprise PeopleTools | CVE-2026-35273 | 9.8 | Network-based, No Authentication Required | Yes (May 27–June 9) | 100+ organizations breached; primarily higher education; data published to leak site |

| Abandoned Package Compromise | Arch Linux User Repository | N/A (supply chain) | Critical | Local execution upon install | Yes (ongoing) | 1,500+ packages modified; atomic-lockfile payload includes credential harvesting, anti-debugging, data exfiltration |


## Affected Products


Google Chrome & Chromium-Based Browsers

  • Chrome (Windows, macOS, Linux)
  • Chromium-based browsers using the V8 engine
  • All versions prior to the June 15, 2026 patch release

  • Oracle PeopleSoft

  • Oracle PeopleSoft Enterprise PeopleTools (all affected versions)
  • Specifically: Environment Management Hub (PSEMHUB) endpoints

  • Arch Linux & AUR

  • 1,500+ Arch User Repository packages modified with malicious preinstall scripts
  • Initial discovery: 400 packages; list expanded as researchers identified additional compromised submissions
  • Packages: primarily abandoned or low-maintenance dependencies (see Sonatype Atomic Arch report for full list)

  • ## Mitigations


    For Chrome Users & Administrators

  • Update to the latest Chrome version immediately (automatic updates are enabled by default, but verify completion on critical systems)
  • For enterprises: force browser updates via Group Policy or Mobile Device Management
  • Monitor for exploit activity in web server logs (look for anomalous V8 bytecode or WASM module behavior)
  • Consider browser isolation or sandboxing technologies for high-risk users

  • For Oracle PeopleSoft Deployments

  • Apply the latest security patch from Oracle immediately
  • If patching cannot be completed within 24 hours, CISA recommends network segmentation: restrict PeopleSoft systems to internal-only access and disable public-facing endpoints
  • Audit access logs for Environment Management Hub (PSEMHUB) between May 27 and June 9 for signs of compromise
  • Search for post-exploitation tools: MeshCentral running on unusual ports, lateral movement to credential storage systems, or unexpected data access

  • For Arch Linux Users & Developers

  • Audit your installed packages against the deleted commit list from Arch Linux (June 12 update)
  • Uninstall any packages from the 1,500+ list and rebuild from official repositories
  • For package maintainers: implement maintenance policies that automatically archive or transfer ownership of inactive packages after 6+ months of inactivity
  • Use hash verification and GPG signatures for all package downloads

  • Supply Chain Defense (All Organizations)

  • Inventory all third-party dependencies, including abandoned ones (use SBOM tools like Syft or CycloneDX)
  • Establish a sunset policy: flag packages without updates in 12+ months for review and replacement
  • Monitor dependency vulnerability feeds in real-time (OSV, GitHub Advisory Database)
  • Block installation of packages flagged as abandoned or unmaintained in your CI/CD pipeline

  • ## References


  • [Google Chrome Security Updates - June 2026](https://chromereleases.googleblog.com)
  • [Oracle Critical Patch Update Advisory - PeopleSoft](https://www.oracle.com/security-alerts/)
  • [Sonatype Report: Atomic Arch Campaign (Supply Chain Attack on AUR)](https://blog.sonatype.com/atomic-arch)
  • [CISA Known Exploited Vulnerabilities (KEV) Catalog - CVE-2026-35273](https://www.cisa.gov/known-exploited-vulnerabilities)
  • [Google Mandiant Threat Intelligence: ShinyHunters Campaign Analysis](https://www.mandiant.com)

  • ---


    ## HackWire Analysis


    The number that should alarm you: five Chrome zero-days in six months. This isn't an anomaly—it's the new baseline. Browser engines have become so complex that the attack surface grows faster than the patch cycle. But what's more dangerous is what this week reveals about infrastructure decay.


    The real vulnerability isn't CVE-2026-11645. It's that organizations are still running authentication systems built in 2015, still have forgotten endpoints listening on internal networks, and still trust that "nobody uses this anymore" means "nobody can exploit it." The Arch Linux compromise demonstrates how this works at scale: 1,500 packages modified because nobody was maintaining them, nobody was verifying them, and nobody was watching. That's not a supply chain attack—that's grave robbing.


    Universities and colleges made up 68% of the PeopleSoft victims. Why? Because student information systems are often deployed once and then forgotten. They're patched slowly, monitored loosely, and isolated just enough that they feel safe. That's the profile ShinyHunters hunts for: critical systems running old code with minimal visibility.


    The lesson for defenders is unsettling: the majority of your exploitable surface isn't in your latest projects. It's in the infrastructure you stopped thinking about three years ago. Start an audit this week. Find every package, every service, every authentication path that hasn't been touched in 12 months. That's your real threat surface. The zero-day exploits are just reminders.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)