ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Google patches Chrome vulnerability with in-the-wild exploit (CVE-2026-2441)

criticalVulnerability exploited in the wildimportance 60CVE-2026-2441

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-2441
Use-After-Free in Google Chromium CSS Rendering Exposes Chrome, Edge, Opera Users

CVE-2026-2441 is a use-after-free (CWE-416) in Google Chromium's CSS handling that a remote attacker can trigger by getting a user's browser to process a crafted HTML page, potentially corrupting the heap. Successful exploitation yields a memory-corruption primitive in the browser; CVSS scoring is not yet available, but Chromium memory-safety flaws of this class can range from crashes to potential code execution depending on how the corruption is leveraged. Anyone running Chromium or a Chromium-based browser — Google Chrome, Microsoft Edge, Opera, and numerous embedded/branded browsers — is potentially affected, making the exposed population effectively all modern browser users. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-02-17, confirming it is being exploited in the wild; EPSS assigns a 22% probability of exploitation within 30 days (98th percentile), no public PoC is known, and any ransomware association is unknown. This lands amid an accelerating series of actively exploited Chrome zero-days in 2026 described in recent reporting, making rapid patching urgent.

Do: Update Chromium and every Chromium-based browser in your estate (Chrome, Edge, Opera, Brave, and embedded browsers) to the latest vendor-stable release — recent reporting places the current patched release at Chrome 153 — and verify installed versions via the browser's About/Settings page. Per CISA's KEV required action, apply mitigations per vendor instructions or follow BOD 22-01 guidance for cloud services, and discontinue use if mitigations are unavailable. Until patched, restrict high-risk users' browsing to trusted sites and monitor vendor advisories for the specific fixed build, since exact version details are not yet published in this data.

8.822% KEV PoC
  • Google Chromium
  • Google Chrome (Chromium-based)
  • Microsoft Edge (Chromium-based)
  • +1 more
massbillions of users (Chromium underpins Chrome alone at ~3B+ users, plus Edge, Opera, and dozens of embedded browsers)
Full article220 words · extracted from helpnetsecurity.com · click to collapse

Google released a security update for Chrome to address a high-severity zero‑day vulnerability (CVE-2026-2441) on Friday.

chrome CVE-2026-2441

“Google is aware that an exploit for CVE-2026-2441 exists in the wild,” the company said.

About CVE-2026-2441

CVE-2026-2441 is a use-after-free bug in the CSS processing component of Google Chrome, which allows a remote attacker “to execute arbitrary code inside a sandbox via a crafted HTML page.”

The vulnerability was reported by researcher Shaheen Fazim on February 11, 2026.

Whether a coincidence or not, came a day after Google shipped a fix for another use-after-free flaw in the same component that was also flagged by researchers.

As per usual, Google did not share more details about the fixed zero-day, nor details about its possible in-the-wild exploitation.

The fix has been shipped in Chrome 145.0.7632.75/76 for Windows/Mac and 144.0.7559.75 for Linux.

If automatic updates are enabled in Chrome, the security patch has likely already been downloaded – you only need to restart the browser for it to take effect. If you update manually, you should check for the latest version and install it as soon as possible.

UPDATE (February 1, 2026, 04:50 a.m. ET):

Vivaldi and Opera have implemented the fix for CVE-2026-2441.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/02/16/google-patches-chrome-vulnerability-with-in-the-wild-exploit-cve-2026-2441/