CVE-2026-0899: Out of bounds memory access in V8
Chromium: CVE-2026-0899 Out of bounds memory access in V8
Other sources
Out of bounds memory access in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-0899?
CVE-2026-0899 has a high severity rating due to its potential for out of bounds memory access, which can lead to memory corruption and exploitation.
How do I fix CVE-2026-0899?
To fix CVE-2026-0899, upgrade Google Chrome to version 144.0.7559.59 or later, and update Microsoft Edge (Chromium-based) as directed in the security release notes.
What versions of software are affected by CVE-2026-0899?
CVE-2026-0899 affects Google Chrome versions before 144.0.7559.59 and Microsoft Edge (Chromium-based) versions before their latest updates.
Is CVE-2026-0899 being actively exploited in the wild?
As of now, there is no public evidence indicating that CVE-2026-0899 is being actively exploited in the wild.
Who is responsible for addressing CVE-2026-0899?
The responsibility for addressing CVE-2026-0899 lies with the respective vendors, Google for Chrome and Microsoft for Edge (Chromium-based), through their regular update processes.