CVE-2026-2441
KEVHIGH 8.8EPSS 22.0%
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS
- 22.02% chance of exploitation in the next 30 days, 97th percentile
- CISA KEV
- added 2026-02-17
- Published
- 2026-02-13
- Updated
- 2026-02-26
Proof-of-concept exploits (7)
- huseyinstif/CVE-2026-2441-PoC136★ · 2026-02-18
- NetVanguard-cmd/CVE-2026-24410★ · 2026-02-24
- D3b0j33t/CVE-2026-2441-PoC0★ · 2026-03-01
- theemperorspath/CVE-2026-2441-PoC0★ · 2026-02-19
- MartinaStarone/CVE-2026-2441
- atiilla/CVE-2026-2441_PoC
- FreeBSDKernel9-0/Proof-Of-Concepts-Releases-For-PS4