Security Affairs newsletter Round 564 by Pierluigi Paganini
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-1670 | The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password" recovery The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password" recovery email address. NVD description · AI analysis pending | 9.3 | <1% | — | — | ||
| CVE-2026-2441 | Use-After-Free in Google Chromium CSS Rendering Exposes Chrome, Edge, Opera Users CVE-2026-2441 is a use-after-free (CWE-416) in Google Chromium's CSS handling that a remote attacker can trigger by getting a user's browser to process a crafted HTML page, potentially corrupting the heap. Successful exploitation yields a memory-corruption primitive in the browser; CVSS scoring is not yet available, but Chromium memory-safety flaws of this class can range from crashes to potential code execution depending on how the corruption is leveraged. Anyone running Chromium or a Chromium-based browser — Google Chrome, Microsoft Edge, Opera, and numerous embedded/branded browsers — is potentially affected, making the exposed population effectively all modern browser users. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-02-17, confirming it is being exploited in the wild; EPSS assigns a 22% probability of exploitation within 30 days (98th percentile), no public PoC is known, and any ransomware association is unknown. This lands amid an accelerating series of actively exploited Chrome zero-days in 2026 described in recent reporting, making rapid patching urgent. Do: Update Chromium and every Chromium-based browser in your estate (Chrome, Edge, Opera, Brave, and embedded browsers) to the latest vendor-stable release — recent reporting places the current patched release at Chrome 153 — and verify installed versions via the browser's About/Settings page. Per CISA's KEV required action, apply mitigations per vendor instructions or follow BOD 22-01 guidance for cloud services, and discontinue use if mitigations are unavailable. Until patched, restrict high-risk users' browsing to trusted sites and monitor vendor advisories for the specific fixed build, since exact version details are not yet published in this data. | 8.8 | 22% | KEV PoC |
| massbillions of users (Chromium underpins Chrome alone at ~3B+ users, plus Edge, Opera, and dozens of embedded browsers) |
Full article869 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
February 22, 2026

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.
Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.
International Press – Newsletter
Snail mail letters target Trezor and Ledger users in crypto-theft attacks
Canada Goose investigating as hackers leak 600K customer records
Fake Incident Report Used in Phishing Campaign
A 47-year-old man associated with the Phobos group was detained by CBZC police officers
Operation DoppelBrand: Massive Fortune 500 Brand Impersonation Campaign Uncovered
SmartLoader Clones Oura Ring MCP to Deploy Supply Chain Attack
Crypto is playing a growing role in human trafficking networks, report shows
Hacking conference Def Con bans three people linked to Epstein
Major operation in Africa targeting online scams nets 651 arrests, recovers USD 4.3 million
Increase in Malware Enabled ATM Jackpotting Incidents Across United States
Inside Southeast Asia’s industrialised fraud factories
Malware
Ninja Browser & Lumma Infostealer
Ghost Tapped: Tracking the Rise of Chinese Tap-to-pay Android Malware
PromptSpy ushers in the era of Android threats using GenAI
NFCShare Android Trojan: NFC card data theft via malicious APK
Hacking
New Chrome Zero-Day (CVE-2026-2441) Under Active Attack — Patch Released
Hacking a pharmacy to get free prescription drugs and more
Manipulating AI memory for profit: The rise of AI Recommendation Poisoning
Four Vulnerabilities Expose a Massive Security Blind Spot in IDE Extensions
Critical Vulnerabilities in Ivanti EPMM Exploited
Notepad++ Fixes Hijacked Update Mechanism Used to Deliver Targeted Malware
Hacker accessed data from 1.2 million bank accounts, French Economy Ministry says
Hackers Expose Age-Verification Software Powering Surveillance Web
German Rail Giant Deutsche Bahn Hit by Large-Scale DDoS Attack
Intelligence and Information Warfare
Starlink restrictions hit Russian forces as Moscow seeks workarounds
From BRICKSTORM to GRIMBOLT: UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day
Journalism under attack: Predator spyware in Angola
A Chinese hack exposes data of 5,000 Italian counterterrorism officers
Cybersecurity
Space emerges as new front in great power competition, officials warn
Sex Toy Maker Tenga Discloses Customer Data Breach
Dior, Louis Vuitton, Tiffany Fined $25 Million in South Korea After Data Breaches
Giving OpenClaw The Keys to Your Kingdom? Read This First
iOS 26.4 beta adds support for testing end-to-end encrypted RCS messaging
Ireland joins regulator smackdown after X’s Grok AI accused of undressing people
2026 OT Cybersecurity Year in Review
Data Protection Commission opens investigation into X (XIUC)
Grok floods X with sexualized images of women and children
Critical infra Honeywell CCTVs vulnerable to auth bypass flaw
Fake Videos, Real Emotions: Viewers Believe AI-Generated Content Even When It’s Labeled
Moltbook, the Social Network for AI Agents, Exposed Real Humans’ Data
PayPal Confirms Data Breach — Money Stolen, Passwords Reset
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
you might also like
leave a comment
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/188332/breaking-news/security-affairs-newsletter-round-564-by-pierluigi-paganini-international-edition.html