CVE-2026-2441: high-severity vulnerability in Google Chrome
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Google Chrome had a flaw in its CSS handling that allowed attackers to run malicious code within the browser's sandbox by tricking users into opening a specially crafted webpage. This could let attackers take control of your browser session and steal sensitive data.
A use-after-free vulnerability in Chrome's CSS parser prior to version 145.0.7632.75 enables remote code execution within the sandbox through a malicious HTML page. The vulnerability is triggered when a crafted webpage causes CSS processing to reference memory that has already been freed, allowing an attacker with no special privileges to execute arbitrary code within the renderer process sandbox.
In the same product, most dangerous first.