← back
CVE-2026-2441highunder attackCWE-416

CVE-2026-2441

76Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 8.8epss 22%
from disclosure to weapon6 days
Published on NVDFeb 13
1st PoC+6d
CISA KEV+4d
exploitation probability
22%top 3% of all CVEs
observed exploitation
yesCISA + VulnCheck
7 public exploit(s)
Action required by CISAfederal deadline: 2026-03-10

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

In short

Google Chrome had a flaw in its CSS handling that allowed attackers to run malicious code within the browser's sandbox by tricking users into opening a specially crafted webpage. This could let attackers take control of your browser session and steal sensitive data.

Technical detail

A use-after-free vulnerability in Chrome's CSS parser prior to version 145.0.7632.75 enables remote code execution within the sandbox through a malicious HTML page. The vulnerability is triggered when a crafted webpage causes CSS processing to reference memory that has already been freed, allowing an attacker with no special privileges to execute arbitrary code within the renderer process sandbox.

Summary generated and translated by AI from the official description.
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
Google · Chrome
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.