# CVE-2026-2441 — Chrome Zero-Day Use-After-Free in CSS Actively Exploited in the Wild

> CVE-2026-2441 is a high-severity Use-After-Free vulnerability in Google Chrome's CSS handling engine, actively exploited in the wild as a zero-day before patching on February 13, 2026. The flaw enables remote code execution via malicious web content, with attackers likely chaining it with sandbox escape and privilege escalation primitives for full system compromise. Reported by independent researcher Shaheen Fazim on February 11, patched within 2 days. Affects all Chrome versions prior to 145.0.7632.75 (Windows/macOS) and 144.0.7559.75 (Linux).

- **Published:** 2026-02-16T03:33:44Z
- **Last reviewed:** 2026-02-16T03:33:44Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0088
- **ID:** TL-2026-0088
- **Severity:** HIGH (CVSS 8.8)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 22 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-2441

## Description

CVE-2026-2441 is a Use-After-Free (UAF) memory corruption vulnerability in Google Chrome's CSS handling subsystem within the Blink rendering engine. The vulnerability stems from improper object lifecycle management during CSS processing, where freed memory can be accessed post-deallocation, creating an exploitable dangling pointer condition.

The vulnerability was discovered being actively exploited in the wild before Google's patch release, classifying it as a zero-day. Attackers weaponized CVE-2026-2441 through malicious web content — victims only needed to visit a crafted webpage for the exploit to trigger. The attack likely involves: (1) triggering the UAF via specially crafted CSS that causes premature object deallocation, (2) heap spraying or type confusion to control the freed memory, (3) achieving arbitrary code execution within the Chrome renderer process, and (4) chaining with additional sandbox escape exploits for full system compromise.

Google restricted full bug details pending update adoption, adhering to its responsible disclosure policy for actively exploited flaws. No specific IOCs have been publicly released, but threat actors may distribute exploits via phishing campaigns, watering hole attacks, or compromised websites.

The vulnerability was reported by independent security researcher Shaheen Fazim on February 11, 2026, and Google released patches just 2 days later on February 13, demonstrating the urgency of the active exploitation. This rapid turnaround confirms the threat was considered severe enough for emergency patch prioritization.

This continues a pattern of CSS-related zero-days in Chrome's Blink engine, underscoring persistent challenges in rendering engine memory safety. Chrome's multi-process architecture and sandbox provide defense-in-depth, but UAF vulnerabilities in the renderer can still be chained with sandbox escapes for full system compromise, particularly targeting Windows, macOS, and Linux platforms.

Organizations should prioritize immediate Chrome updates, monitor for anomalous browser-spawned processes, and review CISA's Known Exploited Vulnerabilities catalog for potential federal mandates.

## MITRE ATT&CK

- T1189 Drive-by Compromise
- T1203 Exploitation for Client Execution
- T1068 Exploitation for Privilege Escalation
- T1211 Exploitation for Stealth
- T1566.002 Spearphishing Link
- T1204.001 Malicious Link
- T1055 Process Injection
- T1005 Data from Local System
- T1071.001 Web Protocols
- T1027 Obfuscated Files or Information
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1218.011 Rundll32
- T1218.005 Mshta
- T1547.001 Registry Run Keys / Startup Folder
- T1555.003 Credentials from Web Browsers

## Sources

- [Chrome 0-Day Vulnerability Actively Exploited by Attackers in the Wild](https://cybersecuritynews.com/chrome-0-day-vulnerability-exploited-wild-2/)
- [Google Chrome Stable Channel Update for Desktop (Feb 13, 2026)](https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_13.html)
- [Google Chrome Extended Stable Updates for Desktop (Feb 13, 2026)](https://chromereleases.googleblog.com/2026/02/extended-stable-updates-for-desktop_13.html)
- [Chromium Security Home](https://www.chromium.org/Home/chromium-security/)
- [MITRE ATT&CK — Drive-by Compromise (T1189)](https://attack.mitre.org/techniques/T1189/)
- [CWE-416 — Use After Free](https://cwe.mitre.org/data/definitions/416.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0088
