Skip to main content

CVE detail

CVE-2026-2441

Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS 8.8 · HighBuzz score 79.6KEV listed1 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 79.6

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 4.6
Mention score
30.0
21 evidence mentions in the snapshot
Diversity score
20.0
11 sources across 6 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
4.6
1 repos · best confidence 0.80
Best PoC traction
1
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
21 source links · newest first
  • Google has fixed 74 vulnerabilities in Chrome, including a high-severity zero-day (CVE-2026-11645) that has been exploited in the wild. “Google is aware that an exploit for CVE-2026-11645 exists in the wild,” the company said in a Monday security advisory. The fix has been shipped in Chrome 149.0.7827.102/.103 for Windows and macOS and Chrome 149.0.7827.102 for Linux, with the update rolling out to users over the coming days and weeks. About CVE-2026-11645 CVE-2026-11645 is an out-of-bounds … More →

    newswww.helpnetsecurity.comJun 9, 2026, 11:24 AM
  • Google fixed a new Chrome zero-day, tracked as CVE-2026-11645, in the V8 JavaScript engine, which is already being exploited in the wild. Google released emergency updates to address a new Chrome zero-day vulnerability, tracked as CVE-2026-11645, that has been exploited in the wild. This flaw is the fifth Chrome zero-day that is being exploited in […]

    newssecurityaffairs.comJun 9, 2026, 10:38 AM
  • The vulnerability is tracked as CVE-2026-11645 and it was reported in late April by an anonymous researcher.

    newswww.securityweek.comJun 9, 2026, 5:57 AM
  • Google has patched another zero-day vulnerability in Chrome, its fourth this year. In patching the vulnerability, tracked as CVE-2026-5281, the company acknowledged that an exploit for it already exists in the wild. According to the report in NIST’s National Vulnerability Database, the vulnerability in Dawn, the implementation of WebGPU used by Chrome, allowed a remote […]

    newswww.csoonline.comApr 3, 2026, 5:29 PM
  • Google fixed a new Chrome zero-day, tracked as CVE-2026-5281, in the WebGPU Dawn component that is already exploited in the wild. Google released Chrome updates fixing 21 vulnerabilities, including a new actively exploited zero-day tracked as CVE-2026-5281. The flaw is a use-after-free bug in Dawn, the WebGPU component used for graphics processing. Due to ongoing […]

    newssecurityaffairs.comApr 1, 2026, 8:41 PM
  • Google has announced fixes for CVE-2026-5281, a zero-day affecting Chrome’s Dawn component.

    newswww.securityweek.comApr 1, 2026, 2:36 PM
  • Google addressed two high-severity vulnerabilities in the Chrome browser that have been exploited in attacks in the wild. Google has released security updates to address two high-severity vulnerabilities, tracked as CVE-2026-3909 and CVE-2026-3910, in the Chrome browser. The company is aware of attacks in the wild exploiting both flaws. “Google is aware that exploits for […]

    newssecurityaffairs.comMar 13, 2026, 10:30 AM
  • 23rd February – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 23rd February, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES France’s Ministry of Economy has disclosed a data breach resulted from an unauthorized access to the national bank account registry FICOBA, impacting information tied to 1.2 million accounts. Exposed data includes names, […]

    vendorresearch.checkpoint.comFeb 23, 2026, 9:01 AM
  • A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. U.S. CISA adds RoundCube Webmail flaws to its Known Exploited Vulnerabilities catalog PayPal discloses extended data […]

    newssecurityaffairs.comFeb 22, 2026, 2:14 PM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Security at AI speed: The new CISO reality The CISO role has changed significantly over the past decade, but according to John White, EMEA Field CISO, Torq, the most disruptive shift is accountability driven by agentic AI. In this Help Net Security interview, White explains how security leaders must design and govern hybrid workforces where humans and AI agents operate … More →

    newswww.helpnetsecurity.comFeb 22, 2026, 9:00 AM
  • Linked URL: https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_13.html | Posted by idoxer | 379 points | 220 comments

    communitynews.ycombinator.comFeb 18, 2026, 4:28 PM
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium CSS, Microsoft Windows, TeamT5 ThreatSonar Anti-Ransomware, and Zimbra flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Google Chromium CSS, Microsoft Windows, TeamT5 ThreatSonar Anti-Ransomware, and Zimbra flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws […]

    newssecurityaffairs.comFeb 18, 2026, 10:55 AM
  • Google has released an emergency update to patch an actively exploited zero-day—the first Chrome zero-day of the year.

    newswww.malwarebytes.comFeb 17, 2026, 12:33 PM
  • Threat actors now have the ability to exploit a new zero-day vulnerability in the Chrome browser, Google has advised IT administrators. The warning comes after Google released a patch for Chrome to plug a use after free memory vulnerability (CVE-2026-2441) in cascading style sheets (CSS), which means the browser’s CSS engine isn’t properly managing memory […]

    newswww.csoonline.comFeb 17, 2026, 12:48 AM
  • Google patched Chrome zero-day CVE-2026-2441, a high-severity CSS use-after-free flaw actively exploited in the wild. Google has released urgent security updates to address a high-severity zero-day vulnerability, tracked as CVE-2026-2441, in Chrome that is already being exploited in real-world attacks. The flaw is a use-after-free bug in the browser’s CSS component. This is the first […]

    newssecurityaffairs.comFeb 16, 2026, 10:10 AM
  • Google released a security update for Chrome to address a high-severity zero‑day vulnerability (CVE-2026-2441) on Friday. “Google is aware that an exploit for CVE-2026-2441 exists in the wild,” the company said. About CVE-2026-2441 CVE-2026-2441 is a use-after-free bug in the CSS processing component of Google Chrome, which allows a remote attacker “to execute arbitrary code inside a sandbox via a crafted HTML page.” The vulnerability was reported by researcher Shaheen Fazim on February 11, 2026. … More →

    newswww.helpnetsecurity.comFeb 16, 2026, 9:49 AM
  • A Chrome 145 update fixes CVE-2026-2441, a vulnerability that can likely be exploited for arbitrary code execution.

    newswww.securityweek.comFeb 16, 2026, 7:54 AM
  • No excerpt available.

    Mitigationwww.cisa.govFeb 13, 2026, 7:17 PM
  • No excerpt available.

    Exploitgithub.comFeb 13, 2026, 7:17 PM
  • https://issues.chromium.org/issues/483569511issues.chromium.org

    No excerpt available.

    Exploitissues.chromium.orgFeb 13, 2026, 7:17 PM
  • https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_13.htmlchromereleases.googleblog.com

    No excerpt available.

    Vendor Advisorychromereleases.googleblog.comFeb 13, 2026, 7:17 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

1 repository references · best confidence 0.80 · max 1 stars

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence