Google has quietly pushed out an emergency Chrome fix after attackers were caught exploiting the browser's first reported zero-day of 2026. The flaw, tracked as CVE-2026-2441 and assigned a "high" CVSS score of 8.8, stems from a use-after-free bug in Chrome's CSS handling that could allow a remote attacker to execute arbitrary code inside the browser's sandbox using a specially crafted HTML page. In other words, a dodgy webpage could be all an attacker needs to get malicious code running inside a victim's browser. Unsurprisingly, Google has rushed out fixes for Chrome with version 145.0.7632.75 for Windows and Mac, and 144.0.7559.75 for Linux, which the Chocolate Factory says will "roll out in the coming days/weeks." Security researcher Shaheen Fazim reported the flaw on February 11, and Google acknowledged that attackers were already exploiting it just two days later – though it's staying tight-lipped on the specifics. The company has not said whether the attacks were targeted or part of a broader exploitation campaign, only that the vulnerability was being abused before a fix was ready. "Google is aware that an exploit for CVE-2026-2441 exists in the wild," its security advisory stated. Google said access to further details about the bug will remain under wraps until most users are patched, and potentially longer if third-party dependencies are involved, a standard move aimed at stopping others from quickly weaponizing the bug. If this all feels a bit familiar, that's becau...
Google patches Chrome zero-day as in-the-wild exploits surface
The Register
·Carly Page
·Published Feb 16, 2026
·Updated
Affected Software
1 affected component
Google Chrome=145.0.7632.75, =144.0.7559.75
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the emergency patch released by Google for a zero-day vulnerability in Chrome.
2
What zero-day vulnerability is mentioned in the article?
The vulnerability is tracked as CVE-2026-2441 and has a high CVSS score of 8.8.
3
What versions of Google Chrome are affected by the vulnerability?
The affected versions of Google Chrome are 145.0.7632.75 and 144.0.7559.75.
4
What security implications are discussed in the article?
The article highlights the potential for in-the-wild exploitation of the zero-day vulnerability.
5
What action has Google taken in response to this security issue?
Google has quietly pushed out an emergency fix to patch the zero-day vulnerability in Chrome.