Google Chrome Zero-Day CVE-2026-2441 Exploited in the Wild
Google released an urgent Chrome for Desktop Stable Channel update to address CVE-2026-2441, a high-severity zero-day that Google said has an exploit active in the wild. The issue is a use-after-free in Chrome’s CSS component, a memory-corruption flaw that can enable code execution in the browser context when a user visits a malicious or compromised webpage; the vulnerability was reported to Google by researcher Shaheen Fazim.
The Canadian Centre for Cyber Security echoed the need to patch Chrome, advising organizations to update beyond affected Stable Channel versions (Windows/Mac prior to 145.0.7632.68 and Linux prior to 144.0.7559.67), while third-party reporting indicated patched Stable builds rolling out to 145.0.7632.75/.76 (Windows/Mac) and 144.0.7559.75 (Linux). Other Canadian Centre advisories published in the same period covered unrelated vendor patches for Tenable Nessus Agent (CVE-2026-2026), Juniper Secure Analytics (JSA), HPE SimpliVity (Intel firmware advisories), and PostgreSQL point releases; these are separate remediation items and not part of the Chrome zero-day event.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
3 events from the most recent confirmed update back to the earliest known activity.
Canadian Centre for Cyber Security urges users to apply Chrome updates
The Canadian Centre for Cyber Security issued advisory AV26-126, directing users and administrators to review Google's Chrome advisory and apply the necessary updates. The notice highlighted the affected Chrome desktop versions and reinforced the need to patch promptly.
Google publishes Chrome advisory and begins rolling out fixes
Google published a security advisory for Chrome Stable on desktop, addressing CVE-2026-2441 and other vulnerabilities. The update applies to versions prior to 145.0.7632.68 on Windows and macOS and prior to 144.0.7559.67 on Linux, and Google said the zero-day was being actively exploited in the wild.
Researcher reports Chrome zero-day CVE-2026-2441 to Google
Security researcher Shaheen Fazim reported CVE-2026-2441 to Google. The vulnerability is a use-after-free memory corruption flaw in Chrome's CSS component that could allow code execution via a malicious webpage.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
2 references tracked. Mallory keeps watching after this page renders.
See the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


