← Vulnerability feed

Vulnerability record · CVE-2026-2441 · published 13 February 2026

CVE-2026-2441: Google Chrome CSS use-after-free enables sandbox code execution

Google · Chrome

Chrome before 145.0.7632.75 contains a use-after-free in CSS handling. A crafted HTML page can trigger the flaw and let a remote attacker run arbitrary code inside the browser sandbox. It is listed in CISA KEV, so exploitation is confirmed in the wild.

8.8 CVSS 3.1 High CISA KEV since 17 Feb 2026 EPSS 55% · top 1.0% CWE-416 · Use after free
8.8CVSS 3.1 base score
55%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
4References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityConfirmed in-the-wild exploitation (KEV) with high CVSS impact, though it requires user interaction and stays within the sandbox.

What it is

Chrome before 145.0.7632.75 contains a use-after-free in CSS handling. A crafted HTML page can trigger the flaw and let a remote attacker run arbitrary code inside the browser sandbox. It is listed in CISA KEV, so exploitation is confirmed in the wild.

Impact

An attacker gains arbitrary code execution within the Chrome sandbox, which can be chained with a sandbox escape for full host compromise. The CVSS vector rates high confidentiality, integrity and availability impact.

Attack surface

Reached over the network by loading a crafted HTML page; the CVSS vector requires user interaction (UI:R) and no privileges (PR:N). No authentication is needed.

Exploitation

CISA KEV lists it as exploited, with a remediation due date of 2026-03-10, and a public PoC reference exists. EPSS is 0.22378 (97.6th percentile), indicating elevated likelihood.

What to do

  • Update Chrome to 145.0.7632.75 or later on all platforms.
  • Apply vendor mitigations or discontinue use if patching is not possible, per CISA KEV guidance.
  • Enforce browser auto-update and verify version compliance across endpoints.
  • Restrict or monitor access to untrusted web content on high-value systems until patched.

Detection

  • Hunt for Chrome versions below 145.0.7632.75 in asset inventories.
  • Monitor for crashes or renderer process anomalies tied to CSS parsing.
  • Review proxy and DNS logs for known exploit-hosting domains and PoC delivery.
  • Alert on unexpected child processes or code execution originating from the browser renderer.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-2441 to the Known Exploited Vulnerabilities catalog on 17 February 2026 as "Google Chromium CSS Use-After-Free Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 10 March 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-2441 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-10585Google Chrome V8 type confusion enables heap corruptionChrome's V8 JavaScript engine contains a type confusion flaw (CWE-843) that can lead to heap corruption when processing a crafted HTML page. It affec…KEVEPSS 5.4%analysed9.8CVE-2014-0497Adobe Flash Player integer underflow allows remote code executionAdobe Flash Player contains an integer underflow (CWE-191) that allows remote attackers to execute arbitrary code via unspecified vectors. The flaw a…KEVEPSS 100%analysed9.6CVE-2024-7971Google Chrome V8 type confusion enables heap corruptionChrome's V8 JavaScript engine contains a type confusion flaw (CWE-843) that lets a crafted HTML page corrupt the heap. It affects Chrome before 128.0…KEVEPSS 21%analysed9.6CVE-2024-5274Google Chrome V8 type confusion allows sandbox code executionGoogle Chrome before 125.0.6422.112 contains a type confusion flaw in the V8 JavaScript engine. A crafted HTML page can trigger the confusion and lea…KEVEPSS 7.5%analysed9.6CVE-2024-4947Google Chrome V8 type confusion allows sandboxed remote code executionGoogle Chrome before 125.0.6422.60 contains a type confusion flaw in the V8 JavaScript engine. A crafted HTML page can trigger the confusion and let …KEVEPSS 15%analysed9.6CVE-2024-4671Google Chrome Visuals use-after-free enables sandbox escapeCVE-2024-4671 is a use-after-free flaw in the Visuals component of Google Chrome prior to 124.0.6367.201. An attacker who has already compromised the…KEVEPSS 8.3%analysed9.6CVE-2023-6345Chrome Skia integer overflow enables sandbox escapeAn integer overflow in Skia in Google Chrome before 119.0.6045.199 lets a remote attacker who already controls the renderer process escape the browse…KEVEPSS 16%analysed9.6CVE-2023-2136Google Chrome Skia integer overflow enables sandbox escapeAn integer overflow in the Skia graphics library in Google Chrome before 112.0.5615.137 lets an attacker who already controls the renderer process es…KEVEPSS 5.7%analysed

Source: NIST National Vulnerability Database (record CVE-2026-2441), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.