Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilityendpoint-software-vulnerabilitywidely-deployed-product-advisoryinitial-access-method

Google Patches Actively Exploited Chrome Zero-Day CVE-2026-2441 in CSS

Updated 3mo agoFirst seen Feb 16, 202615 sources

Google released an out-of-band Chrome Stable update to fix CVE-2026-2441, a high-severity, actively exploited zero-day caused by a use-after-free in Chrome’s CSS processing. The flaw allows a remote attacker to trigger arbitrary code execution within Chrome’s sandbox via a crafted HTML page, making drive-by exploitation feasible if a user visits a malicious or compromised site. The issue is scored CVSS 8.8 and has been characterized as extremely high risk due to confirmed in-the-wild exploitation.

The patched versions include Chrome 145.0.7632.75 (and .76 per platform guidance) for Windows and macOS, and 144.0.7559.75 for Linux; organizations should prioritize rapid browser updates across managed endpoints. Public reporting credits Shaheen Fazim with discovering and reporting the vulnerability (reported Feb 11, 2026), while Google has not disclosed exploit details, threat actor attribution, or targeting information beyond confirming that an exploit exists in the wild.

Share:
Google Patches Actively Exploited Chrome Zero-Day CVE-2026-2441 in CSS
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Feb 20, 20264mo ago

Public proof-of-concept for CVE-2026-2441 is released

A public PoC exploit for CVE-2026-2441 was released, demonstrating how the CSSFontFeatureValuesMap iterator invalidation bug could be triggered on unpatched systems. The disclosure provided additional technical detail on heap grooming and crash behavior across Windows, macOS, and Linux.

Debian releases chromium security update DSA-6146-1

Debian issued security advisory DSA-6146-1 for chromium, indicating downstream remediation for the Chrome/Chromium vulnerability set that included CVE-2026-2441. This reflected vendor patch propagation to Linux distributions.

Feb 18, 20264mo ago

Google publishes follow-up Chrome Stable Channel security advisory

Google published another Chrome security advisory covering newer Stable Channel versions for Windows, macOS, and Linux. Canada's Cyber Centre relayed the notice and recommended users apply the additional updates when available.

CISA adds CVE-2026-2441 to the KEV catalog

CISA added CVE-2026-2441 to its Known Exploited Vulnerabilities catalog, citing active exploitation. Federal civilian agencies were required to remediate the issue under Binding Operational Directive 22-01 by March 10, 2026.

Feb 16, 20264mo ago

Canada's Cyber Centre publishes advisory on exploited Chrome flaw

The Canadian Centre for Cyber Security published advisory AV26-130 referencing Google's February 13 advisory and warning that CVE-2026-2441 was exploited in the wild. It urged users and administrators to review Google's guidance and apply updates.

HKCERT issues alert rating CVE-2026-2441 as extremely high risk

HKCERT issued an alert warning that CVE-2026-2441 was under active exploitation and categorized it as an extremely high-risk browser vulnerability. The alert urged users to update affected Chrome installations promptly.

Feb 13, 20264mo ago

Google releases emergency Chrome update for CVE-2026-2441

Google published an out-of-band Stable Channel security update to fix CVE-2026-2441 and confirmed the vulnerability was being exploited in the wild. Fixed versions were released for Windows, macOS, and Linux, with technical details restricted until more users update.

Feb 11, 20264mo ago

Shaheen Fazim reports Chrome zero-day CVE-2026-2441 to Google

Security researcher Shaheen Fazim reported CVE-2026-2441 to Google. The flaw is a use-after-free / iterator invalidation bug in Chrome's CSS font feature handling that can be triggered via crafted HTML.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

49 LINKEDOpen in app
Threat actors
3 linked
Affected products
19 linked
Brave BrowserChromiumOpera BrowserChromiumOperaChromiumWindowsTvosVisionosBraveIpadosMacosWatchosEdgeIosMacos TahoeChromeIosMacos
Organizations
18 linked
GoogleMicrosoft CorporationVivaldi TechnologiesAppleMozillaRed HatBrave SoftwareNSO GroupIntellexaFortinetIvantiOperaDebianThe Cyber ExpressTinesMediumSecurity AffairsCyberpress
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Google Patches Actively Exploited Chrome Zero-Day CVE-2026-2441 in CSS | Mallory