CVE-2026-2441 · CVSS 8.8 HIGH · EPSS 22% · KEV 2026-02-17 · patch available
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Is CVE-2026-2441 exploited?
Listed in the CISA KEV catalog on 2026-02-17.
Federal remediation due 2026-03-10.
Past that date by 158 days.
EPSS puts exploitation in the next 30 days at 22%.
Public exploit code: proof of concept.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
Release Notes
What PlainSec published about CVE-2026-2441
PlainSec has not published a story about this CVE.