Google has released an emergency security update for Chrome to address the first actively exploited zero-day vulnerability of 2026. The update patches CVE-2026-2441, a high-severity use-after-free flaw in Chrome’s CSS component that attackers are already exploiting in the wild.
The vulnerability is fixed in Chrome version 145.0.7632.75/76 for Windows and macOS, and 144.0.7559.75 for Linux. Google confirmed in its advisory that an exploit for the flaw exists and urged users to update their browsers immediately.
Security researcher Shaheen Fazim reported the vulnerability to Google on February 11, and the company released the patch just two days later. Fazim has previously disclosed multiple high-severity Chrome bugs and has received bug bounty rewards ranging from $7,000 to $8,000, though the payout for this flaw has not yet been announced.
While Google has not shared details about real-world attacks, the vulnerability could potentially allow arbitrary code execution by tricking users into visiting a malicious website. However, such attacks would initially be limited by Chrome’s sandbox, requiring an additional exploit to fully compromise a system. Even so, attackers could leverage the flaw to steal sensitive data, hijack sessions, or launch further attacks.
Chrome saw multiple zero-day vulnerabilities in 2025, with Google tracking six flaws and CISA listing seven in its Known Exploited Vulnerabilities (KEV) catalog, highlighting the continued importance of timely browser updates.

















Comments