Description
Out of bounds memory access in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
Published: 2026-01-20
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Potential Remote Code Exploitation
Action: Patch Browser
AI Analysis

Impact

An out-of-bounds memory access occurs in the V8 JavaScript engine of Google Chrome prior to version 144.0.7559.59, allowing a malicious actor to craft an HTML page that, when rendered by the victim’s browser, may corrupt internal objects. The vulnerability is documented as a buffer overflow (CWE‑125) and a denial of bounds (CWE‑787), both of which can facilitate arbitrary code execution or denial of service on the affected system.

Affected Systems

Google Chrome browsers running on Windows, macOS, and Linux are vulnerable when their version is earlier than 144.0.7559.59. The defect is present in all major operating systems that support Chrome, as indicated by the associated CPE entries.

Risk and Exploitability

The flaw carries a CVSS score of 8.8, reflecting high severity, but the EPSS score of less than 1% signals a low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a remote attacker delivering a crafted HTML page to the victim; this inference is drawn because the official description states that the flaw can be triggered via a crafted HTML page, though the exact delivery method is not explicitly detailed.

Generated by OpenCVE AI on April 18, 2026 at 15:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 144.0.7559.59 or later as soon as possible.
  • If a patch cannot be applied immediately, configure Chrome Enterprise policies to disable JavaScript execution or enforce site isolation for untrusted web content until the update is installed.
  • Enable Chrome’s Site Isolation and Safe Browsing features to reduce the risk of exploitation until the patch is applied.

Generated by OpenCVE AI on April 18, 2026 at 15:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6100-1 chromium security update
History

Thu, 29 Jan 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Wed, 21 Jan 2026 00:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: Out of bounds memory access in V8
References
Metrics threat_severity

None

threat_severity

Important


Tue, 20 Jan 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-787
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 20 Jan 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 20 Jan 2026 04:30:00 +0000

Type Values Removed Values Added
Description Out of bounds memory access in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-02-26T14:44:45.746Z

Reserved: 2026-01-13T18:20:15.455Z

Link: CVE-2026-0899

cve-icon Vulnrichment

Updated: 2026-01-20T13:44:32.712Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-20T05:16:12.480

Modified: 2026-01-29T20:20:16.770

Link: CVE-2026-0899

cve-icon Redhat

Severity : Important

Publid Date: 2026-01-13T00:00:00Z

Links: CVE-2026-0899 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T16:00:04Z

Weaknesses