• News/
  • https://www.theregister.com/2026/02/16/chromes_zeroday/

Google patches Chrome zero-day as in-the-wild exploits surface

The Register
·
Carly Page
·
Published Feb 16, 2026
·
Updated

Google has quietly pushed out an emergency Chrome fix after attackers were caught exploiting the browser's first reported zero-day of 2026. The flaw, tracked as CVE-2026-2441 and assigned a "high" CVSS score of 8.8, stems from a use-after-free bug in Chrome's CSS handling that could allow a remote attacker to execute arbitrary code inside the browser's sandbox using a specially crafted HTML page. In other words, a dodgy webpage could be all an attacker needs to get malicious code running inside a victim's browser. Unsurprisingly, Google has rushed out fixes for Chrome with version 145.0.7632.75 for Windows and Mac, and 144.0.7559.75 for Linux, which the Chocolate Factory says will "roll out in the coming days/weeks." Security researcher Shaheen Fazim reported the flaw on February 11, and Google acknowledged that attackers were already exploiting it just two days later – though it's staying tight-lipped on the specifics. The company has not said whether the attacks were targeted or part of a broader exploitation campaign, only that the vulnerability was being abused before a fix was ready. "Google is aware that an exploit for CVE-2026-2441 exists in the wild," its security advisory stated. Google said access to further details about the bug will remain under wraps until most users are patched, and potentially longer if third-party dependencies are involved, a standard move aimed at stopping others from quickly weaponizing the bug. If this all feels a bit familiar, that's becau...

Read full article

Affected Software

1 affected component
Google Chrome=145.0.7632.75, =144.0.7559.75
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the emergency patch released by Google for a zero-day vulnerability in Chrome.

2

What zero-day vulnerability is mentioned in the article?

The vulnerability is tracked as CVE-2026-2441 and has a high CVSS score of 8.8.

3

What versions of Google Chrome are affected by the vulnerability?

The affected versions of Google Chrome are 145.0.7632.75 and 144.0.7559.75.

4

What security implications are discussed in the article?

The article highlights the potential for in-the-wild exploitation of the zero-day vulnerability.

5

What action has Google taken in response to this security issue?

Google has quietly pushed out an emergency fix to patch the zero-day vulnerability in Chrome.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
Google patches Chrome zero-day as in-the-wild exploits surface - SecAlerts