CVE-2026-2441Active Exploitation(apple / chrome)

CRITICALCVSS 8.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 145 mentions and remains active

Immediate actions

  • Patch apple chrome systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

10.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-10. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-416

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Active exploitation appears in 307 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 461 mentions across 40 observed days

What's happening

  • Active exploitation reported across 307 signals
  • Exploit tool or code specified in 13 signals
  • PoC mentioned or linked in 21 signals
  • Patch or workaround mentioned in 308 signals
  • Technical details provided in 215 signals
  • General: 40 classified signals
  • Peaked 36d ago at 145 mentions (2026-02-16); latest day: 2
  • 461 total mentions across 40 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline461 mentions / 40d
03673109145Mentions · 2026-02-13: 5Mentions · 2026-02-14: 10Mentions · 2026-02-15: 8Mentions · 2026-02-16: 145Mentions · 2026-02-17: 79Mentions · 2026-02-18: 59Mentions · 2026-02-19: 45Mentions · 2026-02-20: 24Mentions · 2026-02-22: 10Mentions · 2026-02-23: 6Mentions · 2026-02-24: 10Mentions · 2026-02-25: 11Mentions · 2026-02-26: 3Mentions · 2026-02-27: 6Mentions · 2026-02-28: 1Mentions · 2026-03-02: 2Mentions · 2026-03-03: 3Mentions · 2026-03-05: 1Mentions · 2026-03-10: 6Mentions · 2026-03-11: 1Mentions · 2026-03-14: 1Mentions · 2026-03-16: 3Mentions · 2026-03-22: 1Mentions · 2026-03-23: 2Mentions · 2026-03-29: 1Mentions · 2026-03-30: 1Mentions · 2026-04-01: 2Mentions · 2026-04-05: 1Mentions · 2026-04-07: 1Mentions · 2026-04-11: 1Mentions · 2026-04-13: 1Mentions · 2026-04-17: 1Mentions · 2026-05-02: 1Mentions · 2026-05-06: 1Mentions · 2026-05-08: 2Mentions · 2026-06-09: 1Mentions · 2026-07-03: 1Mentions · 2026-07-15: 1Mentions · 2026-09-06: 1Mentions · 2026-09-09: 2PoC Mentioned / Linked · 2026-02-16: 2PoC Mentioned / Linked · 2026-02-17: 2PoC Mentioned / Linked · 2026-02-18: 2PoC Mentioned / Linked · 2026-02-19: 2PoC Mentioned / Linked · 2026-02-20: 3PoC Mentioned / Linked · 2026-02-22: 1PoC Mentioned / Linked · 2026-02-24: 1PoC Mentioned / Linked · 2026-02-25: 1PoC Mentioned / Linked · 2026-02-27: 2PoC Mentioned / Linked · 2026-03-02: 1PoC Mentioned / Linked · 2026-03-10: 1PoC Mentioned / Linked · 2026-04-11: 1PoC Mentioned / Linked · 2026-05-06: 1PoC Mentioned / Linked · 2026-05-08: 1Exploit Tool / Code · 2026-02-16: 1Exploit Tool / Code · 2026-02-17: 1Exploit Tool / Code · 2026-02-18: 1Exploit Tool / Code · 2026-02-19: 1Exploit Tool / Code · 2026-02-20: 3Exploit Tool / Code · 2026-02-22: 1Exploit Tool / Code · 2026-02-27: 2Exploit Tool / Code · 2026-03-02: 1Exploit Tool / Code · 2026-03-10: 1Exploit Tool / Code · 2026-05-06: 1Active Exploitation · 2026-02-13: 1Active Exploitation · 2026-02-15: 6Active Exploitation · 2026-02-16: 114Active Exploitation · 2026-02-17: 63Active Exploitation · 2026-02-18: 36Active Exploitation · 2026-02-19: 25Active Exploitation · 2026-02-20: 14Active Exploitation · 2026-02-22: 4Active Exploitation · 2026-02-23: 1Active Exploitation · 2026-02-24: 7Active Exploitation · 2026-02-25: 3Active Exploitation · 2026-02-27: 5Active Exploitation · 2026-03-03: 2Active Exploitation · 2026-03-10: 6Active Exploitation · 2026-03-11: 1Active Exploitation · 2026-03-16: 3Active Exploitation · 2026-03-22: 1Active Exploitation · 2026-03-23: 1Active Exploitation · 2026-03-29: 1Active Exploitation · 2026-04-01: 2Active Exploitation · 2026-04-05: 1Active Exploitation · 2026-04-11: 1Active Exploitation · 2026-04-17: 1Active Exploitation · 2026-05-08: 2Active Exploitation · 2026-06-09: 1Active Exploitation · 2026-07-03: 1Active Exploitation · 2026-07-15: 1Active Exploitation · 2026-09-06: 1Active Exploitation · 2026-09-09: 2Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-02-14: 7Patch / Workaround · 2026-02-15: 4Patch / Workaround · 2026-02-16: 127Patch / Workaround · 2026-02-17: 62Patch / Workaround · 2026-02-18: 36Patch / Workaround · 2026-02-19: 23Patch / Workaround · 2026-02-20: 11Patch / Workaround · 2026-02-22: 2Patch / Workaround · 2026-02-23: 2Patch / Workaround · 2026-02-24: 4Patch / Workaround · 2026-02-25: 4Patch / Workaround · 2026-02-27: 3Patch / Workaround · 2026-03-02: 1Patch / Workaround · 2026-03-05: 1Patch / Workaround · 2026-03-10: 6Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-03-14: 1Patch / Workaround · 2026-03-16: 2Patch / Workaround · 2026-03-22: 1Patch / Workaround · 2026-03-29: 1Patch / Workaround · 2026-04-01: 1Patch / Workaround · 2026-04-17: 1Patch / Workaround · 2026-05-08: 1Patch / Workaround · 2026-06-09: 1Patch / Workaround · 2026-07-15: 1Patch / Workaround · 2026-09-06: 1Patch / Workaround · 2026-09-09: 2Technical Details · 2026-02-13: 4Technical Details · 2026-02-14: 2Technical Details · 2026-02-15: 3Technical Details · 2026-02-16: 67Technical Details · 2026-02-17: 36Technical Details · 2026-02-18: 28Technical Details · 2026-02-19: 19Technical Details · 2026-02-20: 13Technical Details · 2026-02-22: 1Technical Details · 2026-02-23: 2Technical Details · 2026-02-24: 4Technical Details · 2026-02-25: 6Technical Details · 2026-02-26: 1Technical Details · 2026-02-27: 3Technical Details · 2026-03-02: 1Technical Details · 2026-03-03: 1Technical Details · 2026-03-10: 6Technical Details · 2026-03-14: 1Technical Details · 2026-03-16: 2Technical Details · 2026-03-22: 1Technical Details · 2026-04-01: 2Technical Details · 2026-04-05: 1Technical Details · 2026-04-11: 1Technical Details · 2026-04-13: 1Technical Details · 2026-04-17: 1Technical Details · 2026-05-02: 1Technical Details · 2026-05-06: 1Technical Details · 2026-06-09: 1Technical Details · 2026-07-03: 1Technical Details · 2026-07-15: 1Technical Details · 2026-09-06: 1Technical Details · 2026-09-09: 202-1302-1702-2202-2603-0303-1403-2904-0705-0207-0309-09
Signal classification5 categories
Active Exploitation
24352.7%
Patch
13028.2%
General
408.7%
Disclosure
378.0%
PoC
112.4%
Referenced assets259 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-135
Active Exploitation1Disclosure3General1
2026-02-1410
Disclosure2General1Patch7
2026-02-158
Active Exploitation5General1Patch2
2026-02-16145
Active Exploitation86Disclosure7Patch51PoC1
2026-02-1779
Active Exploitation48Disclosure5General4Patch22
2026-02-1859
Active Exploitation28Disclosure3General4Patch22PoC2
2026-02-1945
Active Exploitation22Disclosure4General8Patch9PoC2
2026-02-2024
Active Exploitation11Disclosure3General4Patch5PoC1
2026-02-2210
Active Exploitation3Disclosure1General3Patch2PoC1
2026-02-236
Disclosure1General3Patch2
2026-02-2410
Active Exploitation7Disclosure1General2
2026-02-2511
Active Exploitation3Disclosure2General3Patch2PoC1
2026-02-263
Disclosure1General2
2026-02-276
Active Exploitation5PoC1
2026-02-281
Disclosure1
2026-03-022
Patch1PoC1
2026-03-033
Active Exploitation2General1
2026-03-051
Patch1
2026-03-106
Active Exploitation6
2026-03-111
Active Exploitation1
2026-03-141
Disclosure1
2026-03-163
Active Exploitation3
2026-03-221
Patch1
2026-03-232
Active Exploitation1General1
2026-03-291
Active Exploitation1
2026-03-301
General1
2026-04-012
Active Exploitation1Patch1
2026-04-051
Patch1
2026-04-071
General1
2026-04-111
Active Exploitation1
2026-04-131
Disclosure1
2026-04-171
Active Exploitation1
2026-05-021
Disclosure1
2026-05-061
PoC1
2026-05-082
Active Exploitation2
2026-06-091
Active Exploitation1
2026-07-031
Patch1
2026-07-151
Active Exploitation1
2026-09-061
Active Exploitation1
2026-09-092
Active Exploitation2
Full discourse20 posts
  • Zero Day Engineering@zerodaytraining
    Active Exploitation

    ⚡️ 0-Day Alert - Google Chrome RCE exploit in the wild CVE-2026-2441: Iterator Invalidation UAF in CSS parsing Patched in Chrome Stable channel 145.0.7632.75/76 for Windows/Mac and 144.0.7559.75 for Linux https://t.co/AfR45zSnRC

    Post summary

    CVE-2026-2441 is a use‑after‑free RCE in Chrome that is actively exploited in the wild, and Google has issued patch versions for affected browsers.

    365036818022.8K
    10.0K followersView on X
  • Cyber Security News@The_Cyber_News
    Active Exploitation

    🚨 Chrome 0-Day Vulnerability Actively Exploited by Attackers in the Wild Source: https://cybersecuritynews.com/chrome-0-day-vulnerability-exploited-wild-2/ Google has urgently patched a high-severity zero-day vulnerability in Chrome, confirming active exploitation in the wild. Tracked as CVE-2026-2441, the flaw is a use-after-free bug in the browser's CSS handling. Chrome versions prior to the patches remain exposed to remote code execution attacks, where attackers could leverage the memory corruption to execute arbitrary code via malicious web content. Users should apply updates via Chrome's built-in updater or enterprise management tools. #cybersecuritynews

    Post summary

    A high‑severity zero‑day CVE-2026-2441 in Chrome has been actively exploited via a use‑after‑free bug in CSS handling, prompting an urgent patch from Google and urging users to update immediately.

    159553179021.0K
    47.0K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 Google patched Chrome zero-day CVE-2026-2441, a CVSS 8.8 bug already exploited in attacks. The CSS use-after-free flaw allows sandboxed remote code execution via malicious pages. 🔗 Read → https://thehackernews.com/2026/02/new-chrome-zero-day-cve-2026-2441-under.html First active Chrome zero-day fixed this year. Update now.

    Post summary

    CVE‑2026‑2441 is a use‑after‑free RCE in Chrome that has already been exploited in the wild; Google has since patched the vulnerability and urges users to update.

    57872365747.7K
    1.0M followersView on X
  • Marcus J. Carey@marcusjcarey
    Active Exploitation

    The first Chrome zero-day of 2026 just dropped — and it's already being exploited in the wild. CVE-2026-2441: use-after-free in Chrome's CSS engine (CVSS 8.8). Affects every Chromium browser — Edge, Brave, Opera, Arc. Don't wait for auto-update. Patch now. https://donthackonme.substack.com/p/first-chrome-zero-day-of-2026-is

    Post summary

    The post announces CVE-2026-2441, a use-after-free bug in Chrome's CSS engine, stating it is already being exploited in the wild and urges immediate patching.

    34212079223.9K
    50.4K followersView on X
  • GeekNews@GeekNewsHada
    Patch

    Chrome 윈/맥 버전의 CSS 제로데이 취약점 업데이트 배포 - Google이 크롬 업데이트를 릴리즈, CVE-2026-2441 CSS 관련 제로데이 취약점 포함 - 구글은 이 취약점이 실제 공격에 악용되고 있음을 확인했으며, 사용자들은 즉시 최신 버전으로 업데이트 해야 함 https://news.hada.io/topic?id=26823

    Post summary

    Google has released a Chrome update for CVE‑2026‑2441, a CSS zero‑day that is actively exploited; users are urged to upgrade immediately.

    08111452769.7K
    22.6K followersView on X
  • Hüseyin Tıntaş@1337stif
    PoC

    CVE-2026-2441 PoC Chrome CSSFontFeatureValuesMap Use-After-Free https://github.com/huseyinstif/CVE-2026-2441-PoC

    Post summary

    A proof of concept for CVE-2026-2441, a Chrome use‑after‑free vulnerability, is available on GitHub, but no exploitation evidence or patch information is provided.

    01611024310.9K
    263 followersView on X
  • yousukezan@yousukezan
    Disclosure

    【緊急】Chrome 145にゼロデイ脆弱性(CVE-2026-2441)発覚!Use-after-freeの仕組みを技術的に解説する https://qiita.com/harupython/items/fc4342e1fdc0d13564df #Qiita @PythonHaruより

    Post summary

    An urgent zero‑day vulnerability (CVE‑2026‑2441) affecting Chrome 145 has been discovered, with a technical explanation of the use‑after‑free flaw provided in a Qiita article.

    030092355.9K
    11.3K followersView on X
  • Sekurak@Sekurak
    Active Exploitation

    Kto ma Chrome, niechaj łata. ASAP. Załatano właśnie podatność wykorzystywaną w realnych atakach. CVE-2026-2441.

    Post summary

    CVE-2026-2441 is actively exploited in real attacks; Chrome users are urged to patch immediately.

    31001231620.3K
    41.9K followersView on X
  • xvonfers@xvonfers
    Active Exploitation

    (CVE-2026-2441)[483569511][CSS]Iteration of the CSSFontFeatureValuesMap -> ... -> UAF, exploited ITW https://chromium.googlesource.com/chromium/src/+/e045399a1ecb7ee16e1a7bcbcd8ea59d283dfb07 https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_13.html https://issues.chromium.org/issues/483936078 https://drafts.csswg.org/css-fonts-4/#om-fontfeaturevalues PoC: https://chromium.googlesource.com/chromium/src/+/63f3cb4864c64c677cd60c76c8cb49d37d08319c/third_party/blink/web_tests/external/wpt/css/css-fonts/font_feature_values_map_iteration.html Reported by Shaheen Fazim(@shaheenfazim) https://t.co/1kQxdMsbnL

    Post summary

    CVE‑2026‑2441 is a use‑after‑free in Chrome’s CSSFontFeatureValuesMap that has been exploited in the wild, with a PoC and a patch already released.

    116181396.7K
    4.8K followersView on X
  • CERT@certlv
    Active Exploitation

    ‼️Atklāta augsta riska nulles dienas ievainojamība Google Chrome un citās uz Chromium bāzētās tīmekļa pārlūkprogrammās (CVE-2026-2441). Ievainojamība jau tiek izmantota reālos uzbrukumos. Vairāk: https://cert.lv/lv/2026/02/nulles-dienas-ievainojamiba-chromium-programmatura https://t.co/4eJy0SPWQ1

    Post summary

    A newly discovered zero‑day vulnerability (CVE‑2026‑2441) in Chromium‑based browsers is already being exploited in the wild, as reported by a CERT advisory.

    1460671811.3K
    5.4K followersView on X
  • blackorbird@blackorbird
    PoC

    #maybe CVE-2026-2441 PoC Chrome CSSFontFeatureValuesMap Use-After-Free https://github.com/huseyinstif/CVE-2026-2441-PoC https://t.co/jaEfvFidQy

    Post summary

    A GitHub-based PoC demonstrates a use‑after‑free in Chrome’s CSSFontFeatureValuesMap, but no active exploitation or patches are reported.

    113175395.9K
    39.8K followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    Google patches critical zero-day CVE-2026-2441. Attackers are exploiting this CSS use-after-free flaw in the wild. Update to Chrome 145 immediately. #Chrome #ZeroDay #CVE20262441 #CyberSecurity #InfoSec #PatchNow #BrowserSecurity https://securityonline.info/critical-alert-chrome-zero-day-cve-2026-2441-exploited-in-the-wild/

    Post summary

    CVE-2026-2441, a CSS use‑after‑free flaw in Chrome, is being actively exploited; Google has released a patch and urges users to update to Chrome 145.

    323065275.5K
    10.3K followersView on X
  • Webtekno@webtekno
    Patch

    Google, Chrome tarayıcısında kritik bir güvenlik açığı tespit edildiğini duyurdu. 📌 11 Şubat’ta belirlenen ve “CVE-2026-2441” koduyla anılan açık, bilgisayar korsanlarının rastgele kod çalıştırmasına olanak tanıyordu. Şirket, sorunu gidermek için acil bir güncelleme yayımladı. 📌 Kullanıcıların Windows ve Mac’te 145.0.7632.75/76, Linux’ta ise 144.0.7559.75 sürümüne yükseltme yapması gerekiyor. 📌 Chrome’u güncellemek için: Ayarlar > Chrome hakkında bölümüne girin, güncellemenin otomatik olarak yüklenmesini bekleyin ve tarayıcıyı yeniden başlatın.

    Post summary

    Google has identified a critical Chrome vulnerability (CVE‑2026‑2441) that permits arbitrary code execution and has released an urgent update; users are advised to upgrade to the specified versions.

    321563020.6K
    504.0K followersView on X
  • Autumn Good@autumn_good_35
    General

    @_nat サンドボックス内でのコード実行の脆弱性ですので、この脆弱性単体での影響は限定的かと思います。 https://nvd.nist.gov/vuln/detail/CVE-2026-2441 https://x.com/autumn_good_35/status/2023653146338496944

    Post summary

    The tweet briefly notes a sandbox code‑execution vulnerability (CVE‑2026‑2441) and links to the NVD entry, but it provides no PoC, exploit, patch, or active exploitation details.

    1190421010.8K
    6.7K followersView on X
  • j j@mistymntncop
    Patch

    Patch for CVE-2026-2441 https://github.com/chromium/chromium/commit/e045399a1ecb7ee16e1a7bcbcd8ea59d283dfb07

    Post summary

    A patch commit for CVE‑2026‑2441 is referenced, indicating remediation is available.

    29041203.4K
    3.0K followersView on X
  • Clandestine@akaclandestine
    PoC

    GitHub - huseyinstif/CVE-2026-2441-PoC https://github.com/huseyinstif/CVE-2026-2441-PoC

    Post summary

    A GitHub repository containing a Proof of Concept for CVE-2026-2441 has been shared, indicating potential exploitation but lacking active exploitation evidence, patch details, or technical specifics.

    011037182.9K
    54.7K followersView on X
  • xvonfers@xvonfers
    Disclosure

    (CVE-2026-2441)[483569511][CSS]@font-feature-values -> CSSOM CSSFontFeatureValuesRule.styleset (maplike) -> map.entries() caches FontFeatureAliases HashMap iterator -> map.delete()/map.set() mutates+rehashes backing map -> stale iterator deref in FetchNextItem() -> UAF -> ...

    Post summary

    The snippet details technical aspects of CVE-2026-2441, a use‑after‑free in the CSS engine, but does not mention a PoC, exploit, active attacks, or a patch.

    04135162.4K
    4.8K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    CVE-2026-2441 — Chrome CSSFontFeatureValuesMap Use-After-Free https://github.com/huseyinstif/CVE-2026-2441-PoC

    Post summary

    The snippet announces CVE-2026-2441, a use‑after‑free vulnerability in Chrome’s CSSFontFeatureValuesMap, and directs readers to a GitHub repository containing a PoC that demonstrates the flaw.

    25029192.9K
    150.9K followersView on X
  • Nicolas Krassas@Dinosn
    Patch

    New Chrome Zero-Day (CVE-2026-2441) Under Active Attack — Patch Released https://thehackernews.com/2026/02/new-chrome-zero-day-cve-2026-2441-under.html

    Post summary

    CVE-2026-2441 is a zero‑day vulnerability in Chrome that is actively being exploited, and a patch has been released to mitigate the issue.

    08036114.6K
    151.0K followersView on X
  • blueblue@piedpiper1616
    PoC

    GitHub - D3b0j33t/CVE-2026-2441-PoC - https://github.com/D3b0j33t/CVE-2026-2441-PoC?tab=readme-ov-file

    Post summary

    A GitHub repository provides a proof‑of‑concept for CVE‑2026‑2441, indicating that exploit code is available but no evidence of active exploitation or patch information is present.

    08020182.7K
    5.5K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more