logo

Google fixes first actively exploited Chrome zero-day of 2026

ID: a688e091-3b01-5608-9b7f-947ed5fc4c9c

STIX ID: report--a688e091-3b01-5608-9b7f-947ed5fc4c9c

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-02-16

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Google released urgent updates to address CVE-2026-2441, a high-severity use-after-free vulnerability in Chrome's CSS engine that is being actively exploited in the wild. The flaw allows remote code execution inside the browser sandbox via crafted HTML, was reported by researcher Shaheen Fazim on 2026-02-11, and affects Chromium-based browsers; Chrome Stable received updates (145.0.7632.75/76 for Windows/Mac, 144.0.7559.75 for Linux) to mitigate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.