← back

Google issues emergency Chrome patch for CVE-2026-2441

Kagi News | 2026-02-16 06:38 UTC | source

🔒 Google has pushed an emergency Chrome update to fix a high-severity zero-day vulnerability (CVE-2026-2441) that it says attackers are already exploiting in the wild 12674. Reports describe it as a use-after-free bug in Chrome’s CSS-related code 1264.

The fix is rolling out to Chrome’s Stable channel on Windows, macOS, and Linux. Users should update and then restart Chrome to make sure the patch takes effect 1274.

Google Chrome app shown among mobile browser apps.
Google Chrome app shown among mobile browser apps. — techradar.com

Sources

  1. Google patches first Chrome zero-day of the year - so update now or face attack [techradar.com] (2026-02-16)
  2. Chrome rushes emergency patch for actively exploited zero-day bug [techspot.com] (2026-02-16)
  3. Google fixes exploited Chrome CSS zero-day - theregister.com [google.com] (2026-02-16)
  4. Update Now: Google Fixes the First Active Chrome Zero-Day of 2026 [androidheadlines.com] (2026-02-16)
  5. Government Issues High-Severity Alert For Google Chrome Users [ndtv.com] (2026-02-17)
  6. New Chrome Zero-Day (CVE-2026-2441) Under Active Attack — Patch Released [thehackernews.com] (2026-02-16)
  7. Google patches Chrome zero-day as in-the-wild exploits surface [theregister.com] (2026-02-16)

Highlights

  1. Severity scores: Sources rate the flaw as high severity, with CVSS scores listed as 8.8 6 and 8.3/10 1.
  2. First actively exploited zero-day of 2026: Coverage calls CVE-2026-2441 Chrome’s first actively exploited zero-day patched in 2026, linked to unnamed threat actors 41.
  3. In-sandbox risk: The Register says the CSS flaw could let malicious webpages run code inside Chrome’s sandbox, a reminder that sandboxing isn’t a substitute for patching 7.
Google Chrome branding image used with coverage of the patch.
Google Chrome branding image used with coverage of the patch. — androidheadlines.com

Perspectives

Google: Google shipped an out-of-band Chrome update and is holding back detailed bug information until most users have updated, to limit further exploitation while the patch rolls out.

Indian government advisory: A high-severity government alert urged Chrome users to act quickly to protect their devices from serious cybersecurity threats.

Security press: TechRadar emphasized that unnamed threat actors were already abusing the flaw and called it Chrome’s first zero-day patch of 2026, underscoring the need to update promptly.

Technical Details

Timeline

1
February 11, 2026
Researcher Shaheen Fazim reported CVE-2026-2441 to Google 6.
2
Friday
Google shipped Chrome updates that address the exploited zero-day 6.
3
Monday, February 16
Outlets reported in-the-wild exploitation as the emergency fix rolled out 7.

Action Items