# CyberChef v11.2.0 - Product: CyberChef (https://whatsnew.fyi/product/cyberchef) - Vendor: gchq - Date: 2026-06-17 - Version: v11.2.0 - Original notes: https://github.com/gchq/CyberChef/releases/tag/v11.2.0 - Permalink: https://whatsnew.fyi/product/cyberchef/releases/v11.2.0 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **security** — Add prototype protection to Chart operation - **changed** — Update website references - **fixed** — Add input validation for XOR Checksum blocksize - **fixed** — Fix Reverse highlights unwinding incorrectly - **fixed** — Fix Uint8Array concat crash in Parse IPv4 header - **fixed** — Fix typos and documentation errors - **added** — Add integer check for alphabet size - **fixed** — Validate hexdump width upper bound This release includes a security fix ([#2569]) - Security: Chart operation prototype protection [@C85297] | [#2569] - Update website references [@C85297] | [#2566] - Fix: Add input validation for XOR Checksum blocksize (#2537) [@dweep-js] | [#2542] - Fix: Reverse highlights unwind incorrectly [@kendallgoto] [@C85297] | [#2022] - Fix Uint8Array concat crash in Parse IPv4 header [@Zish19] | [#2409] - Fix typos and documentation errors (bytes→bits, wrong release link, spelling) [@qa2me] [@GCHQDeveloper581] | [#2404] - Add integer check for alphabet size [@heapframe] [@GCHQDeveloper581] | [#2458] - fix: validate hexdump width upper bound [@skyswordw] | [#2514]