Monday , October 5 2026
Chrome 144

Chrome 144 Released, Fixing 10 V8 Engine Vulnerabilities

Google has released Chrome 144 for Windows, Mac, and Linux, fixing 10 security issues, mainly in the V8 JavaScript engine. The rollout is scheduled to reach users progressively over the coming days and weeks.

Critical Security Patches for V8 Engine:

Citrix NetScaler SAML 0-Day Flaw Under Attack

Citrix has put out emergency security updates for a NetScaler SAML flaw that hackers are using. Known as CVE-2026-88779, this...
Read More
Citrix NetScaler SAML 0-Day Flaw Under Attack

Major Danish university breached, 200,000 users at risk

Hackers got into the identity and access management system at the Technical University of Denmark (DTU) and downloaded a lot...
Read More
Major Danish university breached, 200,000 users at risk

Microsoft’s X account hijacked to promote Clippy crypto scam

Microsoft's official X account was taken over to promote an unapproved Clippy-themed cryptocurrency. The tech giant’s X account, with 13...
Read More
Microsoft’s X account hijacked to promote Clippy crypto scam

Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

CPanel has put out security updates to fix three problems in cPanel & WHM. These problems could let attackers take...
Read More
Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Nearly 100,000 Bee Cheng Hiang customers had their email addresses leaked when an employee used an AI tool to generate...
Read More
Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Hackers to exploit a flaw in Zimbra mail servers that are connected to the Internet. They send special emails that...
Read More
Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

Google has said that hackers are using two serious Citrix NetScaler security holes to get root access, set up hidden...
Read More
Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is alerting people about a major flaw in MikroTik RouterOS. This could...
Read More
CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

Apple has launched iOS 26.7.1 and iPadOS 26.7.1 to fix a serious zero-day flaw that it believes might have been...
Read More
Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

JadePuffer Agentic AI targets and destroys Azure’s cloud resources

The JadePuffer ransomware group is attacking Azure users with agent-based attacks that gather information, steal passwords, and damage key components. The...
Read More
JadePuffer Agentic AI targets and destroys Azure’s cloud resources

Chrome version 144.0.7559.59 for Linux and 144.0.7559.59/60 for Windows and Mac includes several security upgrades, fixing six of the ten vulnerabilities affecting the V8 JavaScript engine.

CVE-2026-0899 is a major vulnerability in the V8 engine involving out-of-bounds memory access. Google has released Chrome 144 for Windows, Mac, and Linux, fixing 10 security issues, mainly related to the V8 engine.

The rollout is scheduled to reach users progressively over the coming days and weeks.

CVE-2026-0899 is a serious out-of-bounds memory access vulnerability in the V8 engine. This high-risk issue could let attackers access memory beyond its limits, potentially causing data leaks or system breaches.

CVE ID Severity Component Vulnerability Type
CVE-2026-0899 High V8 Out of bounds memory access
CVE-2026-0900 High V8 Inappropriate implementation
CVE-2026-0901 High Blink Inappropriate implementation
CVE-2026-0902 Medium V8 Inappropriate implementation
CVE-2026-0903 Medium Downloads Insufficient validation
CVE-2026-0904 Medium Digital Credentials Incorrect security UI
CVE-2026-0905 Medium Network Insufficient policy enforcement
CVE-2026-0906 Low Security UI Incorrect security UI
CVE-2026-0907 Low Split View Incorrect security UI
CVE-2026-0908 Low ANGLE Use after free

Additional V8 fixes include CVE-2026-0900 and CVE-2026-0902, which correct vulnerabilities that could be misused by attackers.

CVE-2026-0901 fixes a flaw in Blink, the engine that renders web content.

The update fixes security problems in the Digital Credentials and Split View features. Researcher Hafiizh was rewarded $1,500 for spotting these issues.

A medium-severity vulnerability (CVE-2026-0903) related to input validation in Downloads was fixed, along with network policy enforcement issues.

Google recognized external security researchers for identifying eight of the ten vulnerabilities and awarded over $18,500 in bug bounty rewards.

Users must update their Chrome browsers now for security improvements. Browsers usually update automatically, but users can manually check by going to Settings > About Chrome.

Check Also

Google

Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

Google has said that hackers are using two serious Citrix NetScaler security holes to get …