
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0900 is a High-severity vulnerability involving an inappropriate implementation in the V8 JavaScript engine in Google Chrome, which could allow a remote attacker to potentially exploit object corruption via a crafted HTML page. The vulnerability was reported internally by Google on 2025-12-03 and publicly disclosed on January 13, 2026, as part of the Chrome 144 stable channel release. Affected software includes Google Chrome prior to version 144.0.7559.59 (Linux) / 144.0.7559.60 (Windows/Mac) and Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Release Notes, Microsoft MSRC).
The vulnerability stems from an inappropriate implementation within Chrome's V8 JavaScript engine (CWE classified as NVD-CWE-noinfo due to insufficient public technical detail), which can lead to object corruption in memory. An attacker can exploit this by crafting a malicious HTML page that, when visited by a victim, triggers the flawed V8 code path and potentially corrupts heap objects. Exploitation requires network access and user interaction (visiting a malicious page), but no privileges are required and attack complexity is low. The Chromium issue tracker entry (issues.chromium.org/issues/465730465) is restricted pending broad user patching (Chrome Release Notes).
Successful exploitation could result in high impact to confidentiality, integrity, and availability of the affected system, as object corruption in V8 may be leveraged to achieve arbitrary code execution within the browser's renderer process. This could allow an attacker to access sensitive data, modify browser state or local files accessible to the browser process, or cause a denial of service. Depending on sandbox escape capabilities, further lateral movement or privilege escalation on the host system may be possible (Chrome Release Notes, Microsoft MSRC).
Google has released Chrome 144.0.7559.59 (Linux) and 144.0.7559.60 (Windows/Mac) to address this vulnerability; users should update immediately via Chrome's built-in update mechanism (Chrome Release Notes). Microsoft has also released a corresponding update for Microsoft Edge (Chromium-based) in January 2026 (Microsoft MSRC). Linux distribution packages (Debian, openSUSE, Fedora) have also received updated Chromium packages. No configuration-based workarounds are documented; patching is the recommended remediation. Organizations should prioritize browser updates across all managed endpoints given the high CVSS score and network-based attack vector.
The Chrome 144 release received broad coverage from security news outlets including SecurityOnline, CyberSecurityNews, GBHackers, and Forbes, noting the 10 security fixes included in the update (SecurityOnline, Forbes). The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in Chrome 144 could allow for arbitrary code execution (CIS Advisory). Community reaction was generally focused on the broader Chrome 144 update rather than this specific CVE, with no notable individual researcher commentary specific to CVE-2026-0900.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."