Google released a Chrome Stable channel update to fix CVE-2026-2441, a high-severity use-after-free vulnerability in the browser's CSS component that the company said is being exploited in the wild. The flaw, reported by researcher Shaheen Fazim, affects Chrome on Windows and macOS before 145.0.7632.75/76 and Chrome on Linux before 144.0.7559.75, and Google said technical details would remain restricted until more users had updated.
According to CSIRT.SK, the bug carries a CVSS 3.1 score of 8.8 and can let a remote attacker execute arbitrary code within Chrome's sandbox by luring a victim to a specially crafted HTML page. Google credited its internal security tooling, including sanitizers and fuzzing systems, in the broader effort to identify browser flaws, while defenders were urged to update affected systems immediately to the patched versions or later.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Google released Stable channel updates for Chrome on Windows, macOS, and Linux to fix CVE-2026-2441, a high-severity use-after-free vulnerability in the CSS component. Google said an exploit for the flaw exists in the wild and restricted bug details until more users update.
Security researcher Shaheen Fazim reported the high-severity Chrome CSS use-after-free vulnerability later assigned CVE-2026-2441. Google credited the report in its advisory.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.