Google Patches Actively Exploited Chrome Zero-Day CVE-2026-2441 in CSS
Google released an out-of-band Chrome Stable update to fix CVE-2026-2441, a high-severity, actively exploited zero-day caused by a use-after-free in Chrome’s CSS processing. The flaw allows a remote attacker to trigger arbitrary code execution within Chrome’s sandbox via a crafted HTML page, making drive-by exploitation feasible if a user visits a malicious or compromised site. The issue is scored CVSS 8.8 and has been characterized as extremely high risk due to confirmed in-the-wild exploitation.
The patched versions include Chrome 145.0.7632.75 (and .76 per platform guidance) for Windows and macOS, and 144.0.7559.75 for Linux; organizations should prioritize rapid browser updates across managed endpoints. Public reporting credits Shaheen Fazim with discovering and reporting the vulnerability (reported Feb 11, 2026), while Google has not disclosed exploit details, threat actor attribution, or targeting information beyond confirming that an exploit exists in the wild.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
8 events from the most recent confirmed update back to the earliest known activity.
Public proof-of-concept for CVE-2026-2441 is released
A public PoC exploit for CVE-2026-2441 was released, demonstrating how the CSSFontFeatureValuesMap iterator invalidation bug could be triggered on unpatched systems. The disclosure provided additional technical detail on heap grooming and crash behavior across Windows, macOS, and Linux.
Debian releases chromium security update DSA-6146-1
Debian issued security advisory DSA-6146-1 for chromium, indicating downstream remediation for the Chrome/Chromium vulnerability set that included CVE-2026-2441. This reflected vendor patch propagation to Linux distributions.
Google publishes follow-up Chrome Stable Channel security advisory
Google published another Chrome security advisory covering newer Stable Channel versions for Windows, macOS, and Linux. Canada's Cyber Centre relayed the notice and recommended users apply the additional updates when available.
CISA adds CVE-2026-2441 to the KEV catalog
CISA added CVE-2026-2441 to its Known Exploited Vulnerabilities catalog, citing active exploitation. Federal civilian agencies were required to remediate the issue under Binding Operational Directive 22-01 by March 10, 2026.
Canada's Cyber Centre publishes advisory on exploited Chrome flaw
The Canadian Centre for Cyber Security published advisory AV26-130 referencing Google's February 13 advisory and warning that CVE-2026-2441 was exploited in the wild. It urged users and administrators to review Google's guidance and apply updates.
HKCERT issues alert rating CVE-2026-2441 as extremely high risk
HKCERT issued an alert warning that CVE-2026-2441 was under active exploitation and categorized it as an extremely high-risk browser vulnerability. The alert urged users to update affected Chrome installations promptly.
Google releases emergency Chrome update for CVE-2026-2441
Google published an out-of-band Stable Channel security update to fix CVE-2026-2441 and confirmed the vulnerability was being exploited in the wild. Fixed versions were released for Windows, macOS, and Linux, with technical details restricted until more users update.
Shaheen Fazim reports Chrome zero-day CVE-2026-2441 to Google
Security researcher Shaheen Fazim reported CVE-2026-2441 to Google. The flaw is a use-after-free / iterator invalidation bug in Chrome's CSS font feature handling that can be triggered via crafted HTML.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
15 references tracked. Mallory keeps watching after this page renders.
Update Chrome now: Zero-day bug allows code execution via malicious webpages - DataBreaches.Net
databreaches.net
Open sourcePoC Released for Critical Chrome 0-day Vulnerability Exploited in the Wild
cybersecuritynews.com
Open source[SECURITY] [DSA 6146-1] chromium security update
lists.debian.org
Open sourceThey Hacked the CSS: Inside Chrome’s First Zero-Day of 2026 (CVE-2026-2441) | by Sohan Kanna D | Feb, 2026 | InfoSec Write-ups
infosecwriteups.com
Open sourceChrome RCE Flaw CVE-2026-2441 Exploited In Wild
thecyberexpress.com
Open sourceNew Chrome Zero-Day (CVE-2026-2441) Under Active Attack - Patch Released
thehackernews.com
Open sourceGoogle patches Chrome vulnerability with in-the-wild exploit (CVE-2026-2441) - Help Net Security
helpnetsecurity.com
Open sourceGoogle patches first Chrome zero-day exploited in attacks this year
bleepingcomputer.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


