CVE-2026-2441highunder attackCWE-416

CVE-2026-2441: high-severity vulnerability in Google Chrome

Published · Updated

88Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 8.8epss 55%
from disclosure to weapon5 days
Published on NVDFeb 13
1st PoC+5d
CISA KEV+4d
exploitation probability
55%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
12 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Not affected
1 product — because the vulnerable code is not present in the product
red_hat_products
Action required by CISAfederal deadline: 2026-03-10

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

In short

Google Chrome had a flaw in its CSS handling that allowed attackers to run malicious code within the browser's sandbox by tricking users into opening a specially crafted webpage. This could let attackers take control of your browser session and steal sensitive data.

Technical detail

A use-after-free vulnerability in Chrome's CSS parser prior to version 145.0.7632.75 enables remote code execution within the sandbox through a malicious HTML page. The vulnerability is triggered when a crafted webpage causes CSS processing to reference memory that has already been freed, allowing an attacker with no special privileges to execute arbitrary code within the renderer process sandbox.

Summary generated and translated by AI from the official description.
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
Google · Chrome
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.