CVE-2026-2441
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Google Chrome had a flaw in its CSS handling that allowed attackers to run malicious code within the browser's sandbox by tricking users into opening a specially crafted webpage. This could let attackers take control of your browser session and steal sensitive data.
A use-after-free vulnerability in Chrome's CSS parser prior to version 145.0.7632.75 enables remote code execution within the sandbox through a malicious HTML page. The vulnerability is triggered when a crafted webpage causes CSS processing to reference memory that has already been freed, allowing an attacker with no special privileges to execute arbitrary code within the renderer process sandbox.