New Chrome update fixes actively exploited security flaw

Users are strongly urged to update their browsers immediately.

Users are strongly urged to update their browsers immediately. The Chrome update fixes the first Chrome zero-day vulnerability of 2026, releasing a security update just days after the flaw was discovered.

The critical vulnerability, tracked as CVE-2026-2441 was reportedly being actively exploited in the wild. The flaw allows attackers to execute malicious code within Chrome’s browser sandbox simply by luring victims to a specially crafted website.

With a CVSS 3 score of 8.8, the issue is classified as high risk. Technically, it’s a use-after-free vulnerability in Chrome’s CSS processing engine — a type of memory handling flaw that can enable arbitrary code execution.

Google has disclosed only limited details so far, confirming that exploit code is already circulating. This marks the first zero-day vulnerability reported in Chrome in 2026.

Who is affected?

All Chrome versions prior to 145.0.7632.75 are vulnerable. Users who have not enabled automatic updates should manually update their browser without delay.

Because Chrome’s underlying Chromium engine is widely used, other browsers such as Microsoft Edge, Brave, Opera, and Vivaldi may also be affected. Users of these browsers should install updates as soon as they become available.

Secure versions

According to the official Chrome release announcement, the following versions address the vulnerability:

Linux: 144.0.7559.75

macOS and Linux: 145.0.7632.75 / 145.0.7632.76

Extended Stable (macOS and Windows): 144.0.7559.177

If you are running one of these versions or newer, you are protected. If not, now is the time to update.

about author