Threat reportVulnerabilityTL-2026-0088

CVE-2026-2441 — Chrome Zero-Day Use-After-Free in CSS Actively Exploited in the Wild

highPATCHED

CVE-2026-2441 (TL-2026-0088) is a high-severity software vulnerability scored CVSS 8.8, first published 2026-02-16. It has no confirmed attribution, references 1 CVE (CVE-2026-2441), maps to 16 MITRE ATT&CK techniques (T1005, T1027, T1055), and is covered by 9 detection rules and 22 indicators of compromise.

CVSS
8.8/10High
CVEs
1Referenced vulnerabilities
Techniques
16MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
22Indicators of compromise

Key facts for TL-2026-0088

Threat ID
TL-2026-0088
Severity
HIGH
CVSS
8.8
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
All sectors — browser-based attack affects any organization using Chrome
Target regions
Global
Detection rules
9
Indicators of compromise
22

How CVE-2026-2441 works

CVE-2026-2441 is a high-severity Use-After-Free vulnerability in Google Chrome's CSS handling engine, actively exploited in the wild as a zero-day before patching on February 13, 2026. The flaw enables remote code execution via malicious web content, with attackers likely chaining it with sandbox escape and privilege escalation primitives for full system compromise. Reported by independent researcher Shaheen Fazim on February 11, patched within 2 days. Affects all Chrome versions prior to 145.0.7632.75 (Windows/macOS) and 144.0.7559.75 (Linux).

CVE-2026-2441 is a Use-After-Free (UAF) memory corruption vulnerability in Google Chrome's CSS handling subsystem within the Blink rendering engine. The vulnerability stems from improper object lifecycle management during CSS processing, where freed memory can be accessed post-deallocation, creating an exploitable dangling pointer condition.

The vulnerability was discovered being actively exploited in the wild before Google's patch release, classifying it as a zero-day. Attackers weaponized CVE-2026-2441 through malicious web content — victims only needed to visit a crafted webpage for the exploit to trigger. The attack likely involves: (1) triggering the UAF via specially crafted CSS that causes premature object deallocation, (2) heap spraying or type confusion to control the freed memory, (3) achieving arbitrary code execution within the Chrome renderer process, and (4) chaining with additional sandbox escape exploits for full system compromise.

Google restricted full bug details pending update adoption, adhering to its responsible disclosure policy for actively exploited flaws. No specific IOCs have been publicly released, but threat actors may distribute exploits via phishing campaigns, watering hole attacks, or compromised websites.

The vulnerability was reported by independent security researcher Shaheen Fazim on February 11, 2026, and Google released patches just 2 days later on February 13, demonstrating the urgency of the active exploitation. This rapid turnaround confirms the threat was considered severe enough for emergency patch prioritization.

This continues a pattern of CSS-related zero-days in Chrome's Blink engine, underscoring persistent challenges in rendering engine memory safety. Chrome's multi-process architecture and sandbox provide defense-in-depth, but UAF vulnerabilities in the renderer can still be chained with sandbox escapes for full system compromise, particularly targeting Windows, macOS, and Linux platforms.

Organizations should prioritize immediate Chrome updates, monitor for anomalous browser-spawned processes, and review CISA's Known Exploited Vulnerabilities catalog for potential federal mandates.

MITRE ATT&CK techniques used in TL-2026-0088

collection

T1005 Data from Local System

defense-evasion

T1027 Obfuscated Files or Information; T1055 Process Injection; T1211 Exploitation for Stealth; T1218.005 Mshta; T1218.011 Rundll32

execution

T1059.001 PowerShell; T1059.003 Windows Command Shell; T1203 Exploitation for Client Execution; T1204.001 Malicious Link

privilege-escalation

T1068 Exploitation for Privilege Escalation

command-and-control

T1071.001 Web Protocols

initial-access

T1189 Drive-by Compromise; T1566.002 Spearphishing Link

persistence

T1547.001 Registry Run Keys / Startup Folder

credential-access

T1555.003 Credentials from Web Browsers

Remediation for CVE-2026-2441

Patches

  • Chrome 145.0.7632.75/.76 (Windows/macOS) — released February 13, 2026
  • Chrome 144.0.7559.75 (Linux) — released February 13, 2026

Immediate actions

  • Update Chrome immediately: Windows/macOS to 145.0.7632.75/.76, Linux to 144.0.7559.75
  • Force Chrome updates via enterprise management tools (GCPW, Chrome Browser Cloud Management)
  • Verify update status: chrome://settings/help should show the patched version
  • Monitor for Chrome child processes spawning unexpected system utilities (cmd.exe, powershell.exe, bash)
  • Block known malicious domains distributing exploit content at web gateway/proxy

Workarounds

  • Use alternative non-Chromium browsers (Firefox) for sensitive browsing until update is applied
  • Restrict Chrome usage to trusted sites only via enterprise URL allowlisting
  • Disable JavaScript on untrusted sites via Chrome settings or uBlock Origin (may break functionality)

Longer-term hardening

  • Enable Chrome auto-updates enterprise-wide and monitor compliance
  • Deploy Chrome Enterprise Browser with Site Isolation and strict CSP policies
  • Implement browser isolation technology for high-risk browsing (email links, unknown sites)
  • Deploy EDR with Chrome process chain monitoring for sandbox escape detection
  • Consider enabling Chrome's Enhanced Safe Browsing for real-time URL reputation checks
  • Monitor CISA KEV catalog for mandatory patch deadlines if added

CVEs associated with CVE-2026-2441

CVE-2026-2441

Weaknesses (CWE) in CVE-2026-2441

CWE-416

Timeline of CVE-2026-2441

  • Independent security researcher Shaheen Fazim reports CVE-2026-2441 (Use-After-Free in CSS) to Google Chrome security team. Source: https://cybersecuritynews.com/chrome-0-day-vulnerability-exploited-wild-2/
  • Google releases Chrome Stable Channel Update for Desktop (Feb 12, 2026) — routine update, CVE-2026-2441 not yet patched in this release. Source: https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_12.html
  • Google releases Extended Stable Updates for Desktop also patching CVE-2026-2441, ensuring enterprise users on slower update channels receive the fix. Source: https://chromereleases.googleblog.com/2026/02/extended-stable-updates-for-desktop_13.html
  • Google releases emergency Chrome Stable Channel Update patching CVE-2026-2441. Windows/macOS updated to 145.0.7632.75/.76, Linux to 144.0.7559.75. Google confirms active exploitation in the wild. 2-day turnaround from report to patch. Source: https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_13.html
  • CyberSecurityNews publishes detailed report on CVE-2026-2441 active exploitation, noting attackers likely chain the UAF with sandbox escape and privilege escalation for full system compromise. No specific IOCs released. Source: https://cybersecuritynews.com/chrome-0-day-vulnerability-exploited-wild-2/
  • Chrome patch continues gradual rollout. Google restricts full bug details pending majority user adoption. Organizations urged to force-update Chrome deployments and monitor CISA KEV for potential addition. Source: Google Chrome security policy
  • As of 2026-05-29, CVE-2026-2441 (Chrome CSS use-after-free, CVSS 8.8) remains fully PATCHED: Google's Feb 13 fix (Chrome 145.0.7632.75) and downstream Edge updates are widely deployed, and it sits in CISA KEV (due 2026-03-10, now passed). No open/unpatched flaw, no successor CVE supersedes it; residual risk is only un-updated browsers.

Sources cited for CVE-2026-2441

Detection coverage for TL-2026-0088

As of 2026-02-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0088 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
22 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats