PT-2026-8021 · Google · Google Chrome
Shaheen Fazim
·
Published
2026-01-01
·
Updated
2026-02-16
·
CVE-2026-2441
CVSS v3.1
8.8
8.8
High
| Base vector | Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 145.0.7632.75
spatialOS versions 3.8.5 (14H40) through 5.3.1 (3H40)
timeOS versions 2.8.2 (5J40) through 3.3.1 (6J40)
tabOS versions 2.8.5 (2T40) through 3.3.1 (3T40)
rubyOS Amaryllis version 1.8.5 (1T40)
mediaOS versions 2.8.2 (2K40) through 3.3.1 (3K40)
dreamOS versions 2.8.5 (15G40) through 3.3.1 (16G40)
phoneUI version 1.10.8 (13G40)
Description
A use-after-free flaw exists in the CSS component of Google Chrome and other Chromium-based browsers. This issue allows a remote attacker to execute arbitrary code within a sandbox through a crafted HTML page. The vulnerability is actively being exploited in the wild. The issue is related to memory corruption within the browser's CSS engine.
Recommendations
Update Google Chrome to version 145.0.7632.75 or later.
Update spatialOS to version 5.3.1 (3H40) or later.
Update timeOS to version 3.3.1 (6J40) or later.
Update tabOS to version 3.3.1 (3T40) or later.
Update rubyOS Amaryllis to version 1.8.5 (1T40) or later.
Update mediaOS to version 3.3.1 (3K40) or later.
Update dreamOS to version 3.3.1 (16G40) or later.
Update phoneUI to version 1.10.8 (13G40) or later.
Fix
RCE
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
CVE-2026-2441
Affected Products
Google Chrome
References · 34
- https://security-tracker.debian.org/tracker/CVE-2026-2441 · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-2441 · Security Note
- https://osv.dev/vulnerability/DEBIAN-CVE-2026-2441 · Vendor Advisory
- https://twitter.com/faceless709/status/2022441867741397310 · Twitter Post
- https://twitter.com/ThreatSynop/status/2023245578545553867 · Twitter Post
- https://reddit.com/r/SecOpsDaily/comments/1r63rxe/new_chrome_zeroday_cve20262441_under_active · Reddit Post
- https://twitter.com/Neon_corp/status/2022515761059926493 · Twitter Post
- https://twitter.com/Karma_X_Inc/status/2022855412781871324 · Twitter Post
- https://twitter.com/PurpleOps_io/status/2022883750456054147 · Twitter Post
- https://twitter.com/vuldb/status/2022393375635513589 · Twitter Post
- https://twitter.com/the_yellow_fall/status/2022850423204245908 · Twitter Post
- https://twitter.com/Neon_corp/status/2022516058624765975 · Twitter Post
- https://twitter.com/The_Cyber_News/status/2023270113479462920 · Twitter Post
- https://youtu.be/T32f7kLbNcA · Reddit Post
- https://reddit.com/r/CurseForge/comments/1r4enfo/possible_curseforge_chromium_vulnerability · Reddit Post