Vulnerability record · CVE-2026-2441 · published 13 February 2026
CVE-2026-2441: Google Chrome CSS use-after-free enables sandbox code execution
Google · Chrome
Chrome before 145.0.7632.75 contains a use-after-free in CSS handling. A crafted HTML page can trigger the flaw and let a remote attacker run arbitrary code inside the browser sandbox. It is listed in CISA KEV, so exploitation is confirmed in the wild.
Description
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityConfirmed in-the-wild exploitation (KEV) with high CVSS impact, though it requires user interaction and stays within the sandbox.
What it is
Chrome before 145.0.7632.75 contains a use-after-free in CSS handling. A crafted HTML page can trigger the flaw and let a remote attacker run arbitrary code inside the browser sandbox. It is listed in CISA KEV, so exploitation is confirmed in the wild.
Impact
An attacker gains arbitrary code execution within the Chrome sandbox, which can be chained with a sandbox escape for full host compromise. The CVSS vector rates high confidentiality, integrity and availability impact.
Attack surface
Reached over the network by loading a crafted HTML page; the CVSS vector requires user interaction (UI:R) and no privileges (PR:N). No authentication is needed.
Exploitation
CISA KEV lists it as exploited, with a remediation due date of 2026-03-10, and a public PoC reference exists. EPSS is 0.22378 (97.6th percentile), indicating elevated likelihood.
What to do
- Update Chrome to 145.0.7632.75 or later on all platforms.
- Apply vendor mitigations or discontinue use if patching is not possible, per CISA KEV guidance.
- Enforce browser auto-update and verify version compliance across endpoints.
- Restrict or monitor access to untrusted web content on high-value systems until patched.
Detection
- Hunt for Chrome versions below 145.0.7632.75 in asset inventories.
- Monitor for crashes or renderer process anomalies tied to CSS parsing.
- Review proxy and DNS logs for known exploit-hosting domains and PoC delivery.
- Alert on unexpected child processes or code execution originating from the browser renderer.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-2441 to the Known Exploited Vulnerabilities catalog on 17 February 2026 as "Google Chromium CSS Use-After-Free Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 10 March 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_13.html | Release Notes |
| https://issues.chromium.org/issues/483569511 | Issue TrackingPermissions Required |
| https://github.com/huseyinstif/CVE-2026-2441-PoC/blob/main/poc.html | Exploit |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-2441 | US Government Resource |
Track CVE-2026-2441 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-2441), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.