CVE-2026-0899Out-of-bounds Read in Google Chrome

Severity
8.8HIGHNVD
EPSS
0.0%
top 89.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 20
Latest updateJan 27

Description

Out of bounds memory access in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5google/chrome144.0.7559.59144.0.7559.59
NVDgoogle/chrome< 144.0.7559.59+1
Debianchromium/chromium< 144.0.7559.59-1~deb12u1+2

🔴Vulnerability Details

3
CVEList
CVE-2026-0899: Out of bounds memory access in V8 in Google Chrome prior to 1442026-01-20
GHSA
GHSA-pr2r-wqj6-wp4h: Out of bounds memory access in V8 in Google Chrome prior to 1442026-01-20
OSV
CVE-2026-0899: Out of bounds memory access in V8 in Google Chrome prior to 1442026-01-20

📋Vendor Advisories

4
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-08992026-01-27
Red Hat
chromium-browser: Out of bounds memory access in V82026-01-13
Microsoft
Chromium: CVE-2026-0899 Out of bounds memory access in V82026-01-13
Debian
CVE-2026-0899: chromium - Out of bounds memory access in V8 in Google Chrome prior to 144.0.7559.59 allowe...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-0899 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-0899 — Out-of-bounds Read in Google Chrome | cvebase