Google released an out-of-band Chrome Stable update to fix CVE-2026-2441, a high-severity, actively exploited zero-day caused by a use-after-free in Chrome’s CSS processing. The flaw allows a remote attacker to trigger arbitrary code execution within Chrome’s sandbox via a crafted HTML page, making drive-by exploitation feasible if a user visits a malicious or compromised site. The issue is scored CVSS 8.8 and has been characterized as extremely high risk due to confirmed in-the-wild exploitation.
The patched versions include Chrome 145.0.7632.75 (and .76 per platform guidance) for Windows and macOS, and 144.0.7559.75 for Linux; organizations should prioritize rapid browser updates across managed endpoints. Public reporting credits Shaheen Fazim with discovering and reporting the vulnerability (reported Feb 11, 2026), while Google has not disclosed exploit details, threat actor attribution, or targeting information beyond confirming that an exploit exists in the wild.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
A public PoC exploit for CVE-2026-2441 was released, demonstrating how the CSSFontFeatureValuesMap iterator invalidation bug could be triggered on unpatched systems. The disclosure provided additional technical detail on heap grooming and crash behavior across Windows, macOS, and Linux.
Debian issued security advisory DSA-6146-1 for chromium, indicating downstream remediation for the Chrome/Chromium vulnerability set that included CVE-2026-2441. This reflected vendor patch propagation to Linux distributions.
Google published another Chrome security advisory covering newer Stable Channel versions for Windows, macOS, and Linux. Canada's Cyber Centre relayed the notice and recommended users apply the additional updates when available.
CISA added CVE-2026-2441 to its Known Exploited Vulnerabilities catalog, citing active exploitation. Federal civilian agencies were required to remediate the issue under Binding Operational Directive 22-01 by March 10, 2026.
The Canadian Centre for Cyber Security published advisory AV26-130 referencing Google's February 13 advisory and warning that CVE-2026-2441 was exploited in the wild. It urged users and administrators to review Google's guidance and apply updates.
HKCERT issued an alert warning that CVE-2026-2441 was under active exploitation and categorized it as an extremely high-risk browser vulnerability. The alert urged users to update affected Chrome installations promptly.
Google published an out-of-band Stable Channel security update to fix CVE-2026-2441 and confirmed the vulnerability was being exploited in the wild. Fixed versions were released for Windows, macOS, and Linux, with technical details restricted until more users update.
Security researcher Shaheen Fazim reported CVE-2026-2441 to Google. The flaw is a use-after-free / iterator invalidation bug in Chrome's CSS font feature handling that can be triggered via crafted HTML.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
15 references tracked. Mallory keeps watching after this page renders.
databreaches.net
Open sourcecybersecuritynews.com
Open sourcelists.debian.org
Open sourceinfosecwriteups.com
Open sourcethecyberexpress.com
Open sourcethehackernews.com
Open sourcehelpnetsecurity.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.