Google Warns of In the Wild Exploit as It Patches New Chrome Zero Day
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-2441 | Use-After-Free in Google Chromium CSS Rendering Exposes Chrome, Edge, Opera Users CVE-2026-2441 is a use-after-free (CWE-416) in Google Chromium's CSS handling that a remote attacker can trigger by getting a user's browser to process a crafted HTML page, potentially corrupting the heap. Successful exploitation yields a memory-corruption primitive in the browser; CVSS scoring is not yet available, but Chromium memory-safety flaws of this class can range from crashes to potential code execution depending on how the corruption is leveraged. Anyone running Chromium or a Chromium-based browser — Google Chrome, Microsoft Edge, Opera, and numerous embedded/branded browsers — is potentially affected, making the exposed population effectively all modern browser users. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-02-17, confirming it is being exploited in the wild; EPSS assigns a 22% probability of exploitation within 30 days (98th percentile), no public PoC is known, and any ransomware association is unknown. This lands amid an accelerating series of actively exploited Chrome zero-days in 2026 described in recent reporting, making rapid patching urgent. Do: Update Chromium and every Chromium-based browser in your estate (Chrome, Edge, Opera, Brave, and embedded browsers) to the latest vendor-stable release — recent reporting places the current patched release at Chrome 153 — and verify installed versions via the browser's About/Settings page. Per CISA's KEV required action, apply mitigations per vendor instructions or follow BOD 22-01 guidance for cloud services, and discontinue use if mitigations are unavailable. Until patched, restrict high-risk users' browsing to trusted sites and monitor vendor advisories for the specific fixed build, since exact version details are not yet published in this data. | 8.8 | 22% | KEV PoC |
| massbillions of users (Chromium underpins Chrome alone at ~3B+ users, plus Edge, Opera, and dozens of embedded browsers) |
Full article233 words · extracted from infosecurity-magazine.com · click to collapse
Google has released a security update to patch a newly discovered zero-day in Chrome and the company warned an exploit exists in the wild.
The update, published on February 13, was accompanied by an advisory on CVE-2026-2441, a high severity security vulnerability in Google Chrome for desktop on Windows, Mac and Linux.
As detailed by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD), the bug originated from an issue in Cascading Style Sheets (CSS) allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Google has not provided specific details about CVE-2026-2441 and said, “Access to bug details and links may be kept restricted until a majority of users are updated with a fix.”
The tech giant also confirmed that it “is aware that an exploit for CVE-2026-2441 exists in the wild.”
Discovery of the vulnerability was credited to security researcher, Shaheen Fazim, who reported it on February 11. Google released the security update just two days later.
New security vulnerabilities regularly emerge in browsers. During 2025 Google released eight emergency patches to protect Chrome against new exploits which were actively being abused by attackers.
While security patches to protect against new vulnerabilities are often quickly released, if left unpatched they provide attackers with a commonly exploited point of entry for cyber-attacks against the enterprise.
Image credit: Thaspol Sangsee / Shutterstock.com
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/google-patches-new-in-wild-chrome/