PT-2026-8021 · Google+1 · Google Chrome+1

·

CVE-2026-2441

·

Published

2026-01-01

·

Updated

2026-09-09

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 145.0.7632.75
Description A high-severity use-after-free vulnerability exists in the CSS component of the Blink renderer, specifically within the CSSFontFeatureValuesMap structure. The issue is caused by incorrect iterator invalidation when processing the @font-feature-values property, leading to memory corruption in the browser's render process. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page containing malicious CSS, which allows for arbitrary code execution inside the browser sandbox. This issue has been confirmed as exploited in the wild.
Recommendations Update Google Chrome to version 145.0.7632.75 or 145.0.7632.76 for Windows and macOS. Update Google Chrome to version 144.0.7559.75 for Linux.

Exploit

Fix

RCE

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00482
BDU:2026-01947
BDU:2026-02402
CVE-2026-2441
OPENSUSE-SU-2026:10201-1
OPENSUSE-SU-2026:20248-1
OPENSUSE-SU-2026:20332-1

Affected Products

Google Chrome
Red Os