"One heap" just means they share a marking phase to kill cross-language cycles.
If JS points to a C++ DOM node, and that C++ node holds a JS event listener, standard ref-counting leaks instantly.
They don't share memory pages (V8 moves objects, Oilpan C++ is pinned). They just pass the tracer back and forth: V8 marks JS -> hits a C++ wrapper -> hands off to Oilpan -> Oilpan traces C++ -> hands JS refs back to V8.
Comparing it to the JVM misses the point. You can't run a moving GC on massive C++ codebases. Oilpan is just there to end the nightmare of UAFs and manual cycle-breaking.