
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0899 is an out-of-bounds memory access vulnerability in the V8 JavaScript engine affecting Google Chrome prior to version 144.0.7559.59 (Linux) and 144.0.7559.60 (Windows/Mac), as well as Microsoft Edge (Chromium-based). The vulnerability was reported by researcher @p1nky4745 on 2025-11-08 and publicly disclosed on January 13, 2026, when Google released Chrome 144. It carries a CVSS v3.1 base score of 8.8 (High), assessed by CISA-ADP (Chrome Release, Microsoft MSRC).
The root cause is improper memory boundary enforcement in Chrome's V8 JavaScript engine, classified as both CWE-125 (Out-of-bounds Read) and CWE-787 (Out-of-bounds Write). An attacker can exploit this by crafting a malicious HTML page that, when rendered by the browser, triggers object corruption through out-of-bounds memory access in V8. Exploitation requires user interaction — specifically, a victim visiting an attacker-controlled or compromised webpage — but requires no special privileges. A technical write-up and proof-of-concept analysis was published by STAR Labs in April 2026, titled "Check Removed, Context Confused, Checkmate Achieved" (STAR Labs Blog, Chrome Release).
Successful exploitation could allow a remote attacker to achieve arbitrary code execution within the browser's renderer process, with high confidentiality, integrity, and availability impact. This could lead to complete compromise of the affected browser session, enabling data theft, malware installation, or further lateral movement within the victim's environment. The vulnerability affects all major platforms (Windows, macOS, Linux) running unpatched Chrome or Chromium-based Edge, and also impacts downstream Chromium distributions including Debian, Fedora, openSUSE, Alpine Linux, and Palo Alto Networks products embedding Chromium (Chrome Release, Microsoft MSRC).
cmd.exe, powershell.exe, bash, curl, wget); renderer processes consuming abnormally high memory or crashing repeatedly.%LOCALAPPDATA%\Google\Chrome\User Data\Crashpad\).Google has released Chrome 144.0.7559.59 (Linux) and 144.0.7559.60 (Windows/Mac) to address this vulnerability; users should update immediately via Chrome's built-in update mechanism or by downloading from the official site (Chrome Release). Microsoft has released a corresponding patch for Edge (Chromium); users should apply the latest Edge update via Microsoft Update or the browser's update settings (Microsoft MSRC). Downstream distributions (Debian, Fedora, openSUSE, Alpine, Palo Alto Networks PAN-OS) have also released updated Chromium packages and should be patched promptly. As a temporary workaround where patching is not immediately possible, restrict user access to untrusted or unknown websites and enable automatic browser updates.
The CIS (Center for Internet Security) issued an advisory noting that multiple vulnerabilities in Chrome 144, including CVE-2026-0899, could allow arbitrary code execution. Security media including Forbes, GBHackers, and CyberSecurityNews covered the Chrome 144 release, highlighting the V8 engine flaws as the most significant issues. The STAR Labs research team published a detailed technical blog post in April 2026 analyzing the vulnerability's exploitation mechanics, which drew notable attention from the security research community (STAR Labs Blog). Palo Alto Networks also issued a security advisory (PAN-SA-2026-0002) for their products embedding Chromium.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."