CVE-2026-2313Patch(apple / chrome)

HIGHCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch apple chrome systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Use after free in CSS in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

6.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 16 mentions across 6 observed days

What's happening

  • Active exploitation reported across 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 11 signals
  • Technical details provided in 11 signals
  • Disclosure: 6 classified signals
  • Peaked 4d ago at 4 mentions (2026-02-12); latest day: 2
  • 16 total mentions across 6 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline16 mentions / 6d
01234Mentions · 2026-02-11: 3Mentions · 2026-02-12: 4Mentions · 2026-02-13: 2Mentions · 2026-02-16: 2Mentions · 2026-03-11: 3Mentions · 2026-03-12: 2PoC Mentioned / Linked · 2026-02-13: 1PoC Mentioned / Linked · 2026-02-16: 1Active Exploitation · 2026-02-16: 1Active Exploitation · 2026-03-12: 1Patch / Workaround · 2026-02-12: 4Patch / Workaround · 2026-02-13: 2Patch / Workaround · 2026-02-16: 2Patch / Workaround · 2026-03-11: 2Patch / Workaround · 2026-03-12: 1Technical Details · 2026-02-11: 2Technical Details · 2026-02-12: 3Technical Details · 2026-02-13: 2Technical Details · 2026-02-16: 1Technical Details · 2026-03-11: 2Technical Details · 2026-03-12: 102-1102-1202-1302-1603-1103-12
Signal classification4 categories
Patch
743.8%
Disclosure
637.5%
Active Exploitation
212.5%
General
16.3%
Referenced assets40 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-113
Disclosure3
2026-02-124
Patch4
2026-02-132
Patch2
2026-02-162
Active Exploitation1Patch1
2026-03-113
Disclosure2General1
2026-03-122
Active Exploitation1Disclosure1
Full discourse16 posts
  • Machina Record@MachinaRecord
    Active Exploitation

    【リンク集:2月13日〜16日のセキュリティ関連ニュース/記事】 <脆弱性> ・米CISA、Microsoft SCCMの深刻な脆弱性が攻撃に悪用されたと警告(CVE-2024-43468) https://www.bleepingcomputer.com/news/security/cisa-flags-microsoft-configmgr-rce-flaw-as-exploited-in-attacks/ ・Chrome 145、11件の脆弱性を修正(CVE-2026-2313、CVE-2026-2314他) https://www.securityweek.com/chrome-145-patches-11-vulnerabilities/ ・Ivanti製品の脆弱性を狙ったRCE攻撃、83%は単一の脅威アクターによる犯行か(CVE-2026-1281、CVE-2026-1340) https://www.bleepingcomputer.com/news/security/one-threat-actor-responsible-for-83-percent-of-recent-ivanti-rce-attacks/ ・BeyondTrustの脆弱性、PoC公開直後から悪用が確認される(CVE-2026-1731) https://securityaffairs.com/187962/uncategorized/attackers-exploit-beyondtrust-cve-2026-1731-within-hours-of-poc-release.html <マルウェア・その他脅威> ・UAT-9921がVoidLinkマルウェアを展開、標的はテクノロジーおよび金融部門https://thehackernews.com/2026/02/uat-9921-deploys-voidlink-malware-to.html ・認証情報盗むChrome拡張機能を見つけて削除する方法 https://www.malwarebytes.com/blog/news/2026/02/how-to-find-and-remove-credential-stealing-chrome-extensions ・ユーザーデータをリーク・窃取する有害なChrome拡張機能が300超見つかる https://www.securityweek.com/over-300-malicious-chrome-extensions-caught-leaking-or-stealing-user-data/ ・ClickFix攻撃でClaude LLMのアーティファクトが悪用される Macにインフォスティーラーを拡散 https://www.bleepingcomputer.com/news/security/claude-llm-artifacts-abused-to-push-mac-infostealers-in-clickfix-attack/ ・TrezorとLedgerのユーザーの暗号資産狙う郵便物 https://www.bleepingcomputer.com/news/security/snail-mail-letters-target-trezor-and-ledger-users-in-crypto-theft-attacks/ <データ侵害/サイバー犯罪> ・オランダ大手通信会社Odidoがデータ侵害を受ける 顧客620万人に影響 https://techcrunch.com/2026/02/13/dutch-phone-giant-odido-says-millions-of-customers-affected-by-data-breach/ ・フィンテック企業Figureがデータ侵害を公表 従業員がフィッシング攻撃の被害にhttps://securityaffairs.com/187988/cyber-crime/fintech-firm-figure-disclosed-data-breach-after-employee-phishing-attack.html <AI関連> ・設定ミスのあるAIが国家のインフラ崩壊を引き起こす可能性 https://www.theregister.com/2026/02/13/gartner_ai_infrastructure/ <サイバー戦/APT/国家型アクター/地政学関連> ・ロシア系アクターがウクライナへのCANFAILマルウェア攻撃に関与か Googleが指摘 https://thehackernews.com/2026/02/google-ties-suspected-russian-actor-to.html <逮捕/テイクダウン/制裁/違反/その他法執行関連> ・韓国、データ侵害許したルイヴィトン・ディオール・ティファニーに罰金2,500万ドルを科すhttps://www.bleepingcomputer.com/news/security/louis-vuitton-dior-and-tiffany-fined-25-million-over-data-breaches/ <プライバシー> ・米国土安全保障省、反ICEアカウントの所有者特定へ圧力強化 多くの行政召喚状を送付かhttps://techcrunch.com/2026/02/14/homeland-security-reportedly-sent-hundreds-of-subpoenas-seeking-to-unmask-anti-ice-accounts/ ・Amazon傘下のRingがFlockとの提携計画を終了 プライバシー侵害懸念されるカメラの宣伝騒動から数日後 https://therecord.media/ring-ends-partnership-with-flock-superbowl-ad <リサーチ/攻撃手法/TTP> ・PastebinのコメントがJavaScript使うClickFix攻撃を促進、暗号資産スワップを乗っ取るhttps://www.bleepingcomputer.com/news/security/pastebin-comments-push-clickfix-javascript-attack-to-hijack-crypto-swaps/ ・マイクロソフト、DNSベースのClickFix攻撃の詳細を公開 マルウェアのステージングにNslookupコマンドを使用 https://thehackernews.com/2026/02/microsoft-discloses-dns-based-clickfix.html ・北朝鮮の偽リクルーター、開発者向けコーディング課題にマルウェアを潜ませる https://www.bleepingcomputer.com/news/security/fake-job-recruiters-hide-malware-in-developer-coding-challenges/ ・CRMのコアアプリケーションを攻撃せずに200万件以上のレコードと文書を侵害する方法 https://www.catchify.sa/post/leaking-2m-records-third-party-misconfiguration <政府/政策> ・欧州社会は「恒久的な」サイバー脅威やハイブリッド脅威に適応する必要がある スウェーデンが警告 https://therecord.media/sweden-cyber-threats-europe-permanent ・米国務省サイバー担当官、攻撃者に「実際の代償」を支払わせるべきと主張 https://therecord.media/usa-cyber-actors-consequences ・エストニア諜報機関長官、攻撃的サイバー能力への投資を欧州各国に呼び掛け https://therecord.media/estonia-spy-chief-calls-on-europe-to-invest-in-own-offense <その他> ・独占:パロアルトがハッキング調査報告書から中国を削除か 同国の報復を憂慮した可能性も https://www.reuters.com/world/china/palo-alto-chose-not-tie-china-hacking-campaign-fear-retaliation-beijing-sources-2026-02-12/ ・エプスタイン文書がEVスタートアップとシリコンバレーについて明らかにするもの https://techcrunch.com/2026/02/15/what-the-epstein-files-reveal-about-ev-startups-and-silicon-valley/

    Post summary

    The article highlights several CVEs—Microsoft SCCM, Ivanti, Chrome, and BeyondTrust—reporting active exploitation, PoC releases, and vendor patch updates.

    01011275
    1.2K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Google、Chrome 145のデスクトップ向け安定版で3件の重大な脆弱性を修正(CVE-2026-2313,CVE-2026-2314,CVE-2026-2315) https://rocket-boys.co.jp/security-measures-lab/google-chrome-145-desktop-fixes-three-critical-vulnerabilities-cve-2026-2313-cve-2026-2314-cve-2026-2315/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    Google released patches for three critical CVEs in Chrome 145 desktop stable; the post contains no evidence of exploits, PoC, or active attacks.

    00011138
    318 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers exploited CVE-2026-2313 to inject malicious SQL queries into 250,000+ WordPress sites via the Elementor Ally plugin. The unauthenticated flaw allows direct database access through crafted URLs. Only 36% of affected sites have patched despite fixes being available. #Vulnerability 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/elementor-ally-plugin-sql-injection-vulnerability-2026

    Post summary

    The post reports widespread active exploitation of CVE-2026-2313 via the Elementor Ally plugin, with a significant number of sites still unpatched despite available fixes.

    0000174
    1.9K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Disclosure

    An SQL injection vulnerability (CVE-2026-2313) in the Elementor Ally plugin affects 250k+ WordPress sites. Issue fixed in Ally 4.1.0 but many remain exposed due to slow updates. #WordPress #Elementor #USA https://ift.tt/oT7dqhb

    Post summary

    The CVE-2026-2313 SQL injection in the Elementor Ally plugin affects over 250,000 WordPress sites and has been patched in version 4.1.0, but many sites remain vulnerable due to slow updates.

    00001155
    3.7K followersView on X
  • SempreUpdate@SempreUpdate
    Disclosure

    Vulnerabilidade no Elementor Ally: falha CVE-2026-2313 expõe sites WordPress https://sempreupdate.com.br/vulnerabilidade-elementor-ally-cve-2026-2313-wordpress-6-9-2/

    Post summary

    The brief statement announces the discovery of CVE-2026-2313 impacting Elementor Ally in WordPress, but offers no technical details, exploits, or patch information.

    0000045
    4.7K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    General

    @BleepinComputer I'm a Japanese security researcher who always references your articles. The CVE number listed in this article is not CVE-2026-2313, but I believe the correct number is "CVE-2026-2413" (https://www.cve.org/CVERecord?id=CVE-2026-2413). Please check it out. Thank you as always.

    Post summary

    The post corrects a CVE number and links to the official record, but offers no additional technical, exploit, or mitigation details.

    00000346
    11.4K followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 SQL Injection Flaw in Elementor Ally Leaves 250,000+ WordPress Sites Exposed A high-severity unauthenticated SQL injection flaw in the Elementor Ally plugin, tracked as CVE-2026-2313, can let attackers extract sensitive database data when the plugin’s Remediation module is active and linked to an Elementor account. The issue matters because only about 36% of affected sites have patched to version 4.1.0, leaving a large WordPress attack surface exposed to straightforward database compromise attempts. 🎯 Target: Global/WordPress Sites #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.bleepingcomputer.com/news/security/sqli-flaw-in-elementor-ally-plugin-impacts-250k-plus-wordpress-sites/

    Post summary

    A high‑severity SQL injection vulnerability (CVE‑2026‑2313) in Elementor Ally plugin threatens over 250,000 WordPress sites, with only a minority patched to version 4.1.0.

    0000013
    283 followersView on X
  • Machina Record@MachinaRecord
    Patch

    📬郵便物でTrezorとLedgerユーザーの暗号資産狙う物理的フィッシング攻撃 🩹Chrome 145、11件の脆弱性を修正(CVE-2026-2313、CVE-2026-2314他) 〜サイバーセキュリティ週末の話題〜 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/43875/

    Post summary

    The alert highlights a physical phishing attack targeting Trezor and Ledger users and reports that Chrome 145 has released patches for CVE-2026-2313, CVE-2026-2314, among other vulnerabilities.

    00000175
    1.2K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A use-after-free vulnerability (CVE-2026-2313) in `Chromium`'s CSS engine could lead to heap corruption via crafted HTML, potentially enabling code execution. Update `Google Chrome` and `Chromium`-based browsers. #Chromium #Infosec #CVE https://www.pulsepatch.io/posts/cve-2026-2313-chromium-use-after-free

    Post summary

    Chromium’s CSS engine contains a use‑after‑free flaw that can corrupt the heap and potentially allow code execution; users are advised to update Google Chrome and Chromium‑based browsers.

    0000038
    1 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Chrome 145 ships security update fixing 11 bugs, including 3 high-severity flaws Chrome 145 (145.0.7632.45/46) patches 11 vulnerabilities, including three high-severity issues: a CSS use-after-free (CVE-2026-2313), a heap buffer overflow in Codecs (CVE-2026-2314), and a WebGPU inappropriate implementation bug (CVE-2026-2315); Google says none are known to be exploited in the wild. Organizations should still push the update quickly given browser-bug exploitability and user exposure at scale. 🎯 Target: Global/Chrome Users #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.securityweek.com/chrome-145-patches-11-vulnerabilities/

    Post summary

    The text announces that Chrome 145 includes security updates for 11 vulnerabilities, including three high-severity issues, and urges users to install the patch, noting no known exploitation in the wild.

    0000040
    191 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Chrome 145 Security Update Patches 11 Bugs, Including High-Severity Code-Execution Flaws Google shipped Chrome 145 for Windows/macOS/Linux fixing 11 vulnerabilities, led by CVE-2026-2313 (high, use-after-free in CSS) plus CVE-2026-2314 (high, heap overflow in Codecs) and CVE-2026-2315 (high, WebGPU), all with potential code-execution impact. Users should update to 145.0.7632.45 (Linux) or 145.0.7632.45/46 (Windows/Mac) as the rollout progresses. 🎯 Target: Global / Chrome Users (Windows, macOS, Linux) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/chrome-security-update-patch-vulnerabilities/

    Post summary

    Google released Chrome 145, which patches 11 high‑severity vulnerabilities—including CVE‑2026‑2313, CVE‑2026‑2314, and CVE‑2026‑2315—and urges users to update to the latest version.

    00000108
    191 followersView on X
  • CSIRT TELCONET@CSIRT_Telconet
    Patch

    Google lanzó Chrome 145 para Windows, Mac y Linux, corrigiendo 11 vulnerabilidades, incluida la CVE-2026-2313 (use-after-free en CSS) de alta severidad, que podría permitir ejecución remota de código. Se recomienda actualizar cuanto antes. Mas información: https://csirt.telconet.net/comunicacion/boletines-servicios/actualizacion-critica-de-seguridad-en-google-chrome-145-corrige-vulnerabilidades-para-ejecucion-remota-de-codigo/ https://t.co/bPCzdUDXO9

    Post summary

    Google released Chrome 145, fixing CVE-2026-2313—a use‑after‑free in CSS that could lead to remote code execution; users are urged to apply the update promptly.

    00000128
    804 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Chrome 145 Emergency Update Fixes 11 High-Severity Browser Bugs Linked to Code Execution Risk Google shipped Chrome 145.0.7632.45 (announced Feb 10) patching 11 security flaws—including high-severity use-after-free and heap buffer overflow issues (e.g., CVE-2026-2313 in CSS, CVE-2026-2314 in Codecs, CVE-2026-2315 in WebGPU)—that could enable remote code execution or memory corruption via malicious content. This matters because browser RCE is a top initial-access path, so fast patch adoption reduces drive-by and phishing-delivered exploit success. 🎯 Target: Global / Chrome Users (Windows, macOS, Linux) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/chrome-security-update-patches-vulnerabilities-2/

    Post summary

    Chrome 145 emergency update fixes 11 high‑severity vulnerabilities that could lead to remote code execution; the patch is available and should be applied promptly.

    0000036
    191 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2313 Use-After-Free in Chrome CSS Rendering Engine Enables Remote Code Executi... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2313 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    A new Chrome CSS rendering engine use‑after‑free vulnerability (CVE‑2026‑2313) is reported, potentially allowing remote code execution; no exploit, patch, or real‑world usage details are provided.

    0000050
    4.0K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    The severity is increased for this new vulnerability affecting Google Chrome (CVE-2026-2313) https://vuldb.com/?id.345564

    Post summary

    The post announces a new Google Chrome vulnerability (CVE-2026-2313) with higher severity, referencing a vulnerability database entry but providing no technical or exploit details.

    0000074
    2.1K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-2313: HIGH] Use after free in CSS in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)#cve,CVE-2026-2313,#cybersecurity https://cvefind.com/CVE-2026-2313

    Post summary

    The post announces CVE‑2026‑2313, describing a use‑after‑free in Chrome’s CSS engine that could cause heap corruption through a crafted HTML page, and highlights its high severity.

    0000061
    583 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more