HOMEVULNERABILITIESCVE-2026-2441
HIGHCISA KEVIN THE WILD

CVE-2026-2441

CWE-416Published: February 17, 2026· Updated: Feb 18, 2026

8.8
CVSS v3.1
EPSS:0.34%probability of exploitation in 30 daysPercentile:56.7th

Official Description

Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

NVD Source

CISA KEV Advisory

Google Chromium CSS Use-After-Free Vulnerability

Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Added to KEV: 2026-02-17Federal patch deadline: 2026-03-10
Required Action (CISA)

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Risk Analysis

This use-after-free vulnerability in Google Chromium CSS could lead to heap corruption and potential code execution by a remote attacker via a crafted HTML page. With a CVSS score of 8.8 and confirmed exploitation in the wild, this is a critical vulnerability despite a low EPSS score of 0.00345.

This vulnerability is actively being exploited in the wild, as confirmed by its presence in CISA's KEV catalog. It is remotely exploitable with low complexity.

Recommended Action

Users of Google Chrome, Microsoft Edge, Opera, and other Chromium-based browsers on Linux, Windows, and macOS should update to the latest versions immediately to prevent exploitation.

Generated by the CTIWATCH analysis pipeline from this CVE's metadata (CVSS, EPSS, KEV status, exploit intelligence). Verify against vendor advisories before acting.

Technical Analysis

CVE-2026-2441 can be exploited remotely over the network without requiring physical or adjacent access, significantly expanding the attack surface for threat actors.

Exploitation does not require any privileges, though user interaction (Required) is needed, which slightly reduces the risk of mass automated attacks.

A successful exploit results in complete confidentiality breach (data exposure), full integrity compromise (data manipulation), availability disruption (denial of service), with a CVSS base score of 8.8.

CISA has added CVE-2026-2441 to the Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. U.S. federal agencies are required to patch this within the mandated timeframe, and all organizations should treat remediation as urgent.

From a weakness classification perspective (CWE-416): Use-after-free vulnerabilities involve accessing memory after it has been freed, often enabling arbitrary code execution.

CVSS v3.1 Vector Breakdown

Exploitability
Attack VectorNetwork
Attack ComplexityLow
Privileges Req.None
User InteractionRequired
ScopeUnchanged
Impact
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Vendors & Products

Apple1 product
macos
Google1 product
chrome
Linux1 product
linux kernel
Microsoft1 product
windows
Source: NVD CPE · 4 total CPE entries

Exploit & PoC Resources

ACTIVE EXPLOITATIONConfirmed exploitation in the wild
External links open in a new tab. Always verify in a controlled environment before use.

News & Research Mentioning CVE-2026-2441

CISA Flags Four Security Flaws Under Active Exploitation in Latest KEV Update
The Hacker News· Feb 18, 2026

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The list of vulnerabilities is as follows - CVE-2026-2441 (CVSS score: 8.8) - A use-after-free vulnerability in Google Chrome that could allow a remote attacker to potentially exploit heap [xlite_meta score:40 src:The Hacker News xlite_fp:8727d3b64f96649495c14fabd1ef2934a4102e99c713d397eb9b18e9f581e698]

CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA Alerts· Feb 17, 2026

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2008-0015 Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability CVE-2020-7796 Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability CVE-2024-7694 TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability CVE-2026-2441 Google Chromium CSS Use-After-Free Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the [xlite_meta score:57 src:CISA Alerts xlite_fp:0151606efb7c3597e4acbd0d824dcee382a174d70f7753422aa0e45dddd065c7]

New Chrome Zero-Day (CVE-2026-2441) Under Active Attack — Patch Released
The Hacker News· Feb 16, 2026

Google on Friday released security updates for its Chrome browser to address a security flaw that it said has been exploited in the wild. The high-severity vulnerability, tracked as CVE-2026-2441 (CVSS score: 8.8), has been described as a use-after-free bug in CSS. Security researcher Shaheen Fazim has been credited with discovering and reporting the shortcoming on February 11, 2026. "Use after [xlite_meta score:43 src:The Hacker News xlite_fp:722f82b99adf46b210cc5ca9b54f7031a6cb1d060e4cafa1c83da8023f0b3e72]

All References (2)

Quick Facts

CVE IDCVE-2026-2441
CVSS Score8.8 / 10
SeverityHIGH
WeaknessCWE-416
CISA KEVYES — Active Exploitation
ExploitIN THE WILD
EPSS (30d)0.34%
Affected4 vendors
PublishedFeb 17, 2026

Known Threat Actors

wa
financial
vect
financial
core
financial

Related CVEs (CWE-416)

Recommended Actions

  • Apply vendor patches immediately
  • Monitor CVE-2026-2441 in threat intel feeds
  • Review IDS/IPS signatures for exploitation attempts
  • !CISA KEV: Federal agencies must patch per BOD 22-01 timeline
  • !Active exploitation confirmed — treat as P1
Data sourced from NVD (NIST), CISA KEV, and EPSS (FIRST). Analysis generated by CTIWATCH.COM. CVE data is provided under the NVD usage policy.