Cyber Security News

Chrome 144 Released With Fix for 10 Vulnerabilities in V8 JavaScript Engine

Google has officially released Chrome 144 to the stable channel for Windows, Mac, and Linux, addressing 10 security vulnerabilities with a primary focus on the V8 JavaScript engine.

The rollout is scheduled to reach users progressively over the coming days and weeks.

Critical Security Patches for V8 Engine

Chrome version 144.0.7559.59 for Linux and 144.0.7559.59/60 for Windows and Mac brings multiple security improvements, with six of the ten fixed vulnerabilities directly affecting the V8 JavaScript engine.

The most severe issue, CVE-2026-0899, involves an out-of-bounds memory access vulnerability in the V8 engine.

This high-severity flaw could allow attackers to access memory outside allocated boundaries, leading to information disclosure or system compromise.

CVE IDSeverityComponentVulnerability Type
CVE-2026-0899HighV8Out of bounds memory access
CVE-2026-0900HighV8Inappropriate implementation
CVE-2026-0901HighBlinkInappropriate implementation
CVE-2026-0902MediumV8Inappropriate implementation
CVE-2026-0903MediumDownloadsInsufficient validation
CVE-2026-0904MediumDigital CredentialsIncorrect security UI
CVE-2026-0905MediumNetworkInsufficient policy enforcement
CVE-2026-0906LowSecurity UIIncorrect security UI
CVE-2026-0907LowSplit ViewIncorrect security UI
CVE-2026-0908LowANGLEUse after free

Additional V8-related fixes include CVE-2026-0900 and CVE-2026-0902, both of which address improper implementations that could be exploited by malicious actors.

Beyond V8 engine fixes, Chrome 144 addresses vulnerabilities across multiple browser components.

CVE-2026-0901 resolves an inappropriate implementation in Blink, the rendering engine responsible for displaying web content.

The update also addresses security issues in the Digital Credentials and Split View features, with researcher Hafiizh receiving rewards totaling $1,500 for identifying these flaws.

A medium-severity vulnerability in Downloads (CVE-2026-0903) affecting input validation was fixed, along with network policy enforcement issues.

Google credited external security researchers with discovering eight of the ten vulnerabilities and paid out over $18,500 in bug bounty rewards.

Users should update their Chrome browsers immediately to benefit from these security enhancements.

The browser typically updates automatically, but users can manually check for updates by navigating to Settings > About Chrome.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago