logo

CVE-2026-2441: Chrome Zero-Day Enables In-Sandbox Code Execution

ID: 2abdc5cd-7a0e-5efa-b547-ba42c1b92ee6

STIX ID: report--2abdc5cd-7a0e-5efa-b547-ba42c1b92ee6

Feed Name: SOCRadar Blog

Threat Score
85/100

Date Published: 2026-02-16

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

Google patched CVE-2026-2441 (CVSS 8.8), a Chrome use-after-free in CSS that enables arbitrary in-sandbox code execution and is being exploited in the wild; organizations should urgently update Chrome to the fixed builds (Windows/macOS Stable 145.0.7632.75+, Linux Stable 144.0.7559.75+, Extended Stable 144.0.7559.177+) and verify browser restarts, prioritize endpoints below fixed versions, and apply short-term compensating controls while tracking Chromium-based vendor updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.