Security
Zero-day Google Chrome vulnerability CVE-2026-2441 actively exploited in attacks
Image: Primary Google reported a security incident on February 16, 2026. The incident involved a cyberattack that exploited a zero-day vulnerability in the Google Chrome browser. Unauthorized access was identified on February 13, 2026.
Google released emergency security updates for CVE-2026-2441 on February 13, 2026. The vulnerability is a use-after-free bug in the CSS component of the browser. It allows remote attackers to execute code or cause browser crashes.
The incident is classified at a high severity level. The flaw permits remote code execution within the browser sandbox. This creates risks of unauthorized system access or data corruption for users who do not apply updates.
No specific threat actor has been identified. The vulnerability was confirmed to be actively exploited in the wild before patches became available. Potential impacts include exposure of browser session data and credentials if users visit malicious HTML pages.
Users of Google Chrome and other Chromium-based browsers face risks of arbitrary code execution and service disruption. Immediate application of the latest versions is recommended. Enabling automatic updates and monitoring account activity are advised steps.
Sources
Evidence entered
Admission Evidence and chronology passed Security
Publication receipt Entered the validated Newswire
In this story
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from UpGuard and reviewed by the T&B editorial agent team.
Back to Newswire
