CVE-2026-2441

9.5 CISA KEV

Google · Chrome

Google Chrome is vulnerable to a "Use After Free" condition in its CSS engine, which could allow a remote attacker to execute arbitrary code via a crafted webpage.

Executive summary

Google Chrome versions prior to 145 are vulnerable to a high-severity Use After Free flaw that could lead to remote code execution and browser compromise.

Vulnerability

This vulnerability is a memory corruption issue (Use After Free) within the CSS component of the browser. An unauthenticated remote attacker can exploit this by enticing a user to visit a specially crafted website, leading to a crash or arbitrary code execution.

Business impact

Exploitation of this flaw can lead to the compromise of the user's workstation, allowing for the theft of browser-stored credentials, session hijacking, or the installation of further malware. Given Chrome's ubiquity, this poses a significant risk to corporate endpoint security. The CVSS score of 8.8 reflects the high severity of remote code execution.

Remediation

Immediate Action: Update Google Chrome to version 145 or later across all endpoints immediately.

Proactive Monitoring: Utilize endpoint detection and response (EDR) tools to monitor for unusual browser crashes or suspicious child processes spawned by Chrome.

Compensating Controls: Implement web filtering to prevent users from accessing known malicious or untrusted websites that might host exploit code.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Browser updates are a critical component of endpoint hygiene. Administrators should ensure that auto-update mechanisms are functioning correctly and that all systems are running at least version 145 to mitigate this risk.

More Google CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section
  3. Published in the daily brief high section
  4. Published in the daily brief kev section
  5. Published in the daily brief kev section
  6. Published in the daily brief kev section
  7. Published in the daily brief kev section
  8. Published in the daily brief kev section
  9. Published in the daily brief kev section
  10. Published in the daily brief kev section
  11. Published in the daily brief kev section
  12. Published in the daily brief kev section
  13. Published in the daily brief kev section
  14. Published in the daily brief kev section
  15. Published in the daily brief kev section
  16. Published in the daily brief kev section
  17. Published in the daily brief kev section
  18. Published in the daily brief kev section
  19. Published in the daily brief kev section
  20. Published in the daily brief kev section
  21. Published in the daily brief kev section
  22. Published in the daily brief kev section
  23. Published in the daily brief kev section
  24. Fix documented version 145.0.7632.75 per CVE record