A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection Platforms. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Read More
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-2441

CVE-2026-2441: Google Chrome Use After Free Vulnerability

CVE-2026-2441 is a use after free vulnerability in Google Chrome's CSS component that enables remote code execution within a sandbox via malicious HTML. This article covers the technical details, affected versions, and steps to mitigate.

Updated: May 15, 2026

CVE-2026-2441 Overview

CVE-2026-2441 is a use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation of Google Chrome prior to version 145.0.7632.75. A remote attacker can execute arbitrary code inside the renderer sandbox by serving a crafted HTML page to a victim browser. The flaw is tracked under [CWE-416: Use After Free] and affects Chrome across Windows, macOS, and Linux. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. A public proof-of-concept is available, which raises the urgency for organizations to deploy the Chrome stable channel update.

Critical Impact

Remote attackers can achieve arbitrary code execution within the Chrome renderer sandbox by luring a user to a malicious web page, enabling browser exploitation that can chain into full system compromise.

Affected Products

  • Google Chrome versions prior to 145.0.7632.75 on Windows
  • Google Chrome versions prior to 145.0.7632.75 on macOS
  • Google Chrome versions prior to 145.0.7632.75 on Linux

Discovery Timeline

  • 2026-02-13 - CVE-2026-2441 published to NVD following Google's stable channel update
  • 2026-02-23 - Last updated in NVD database

Technical Details for CVE-2026-2441

Vulnerability Analysis

The defect resides in Chrome's Blink CSS engine, which manages style computation, layout, and the lifecycle of style-related objects. A use-after-free condition arises when CSS object references continue to be used after the underlying memory has been released. Attackers manipulate the document and style state through scripted DOM and CSS operations to trigger the dangling pointer dereference. Once the freed memory is reclaimed and shaped by attacker-controlled content, the resulting type confusion can be steered into arbitrary code execution inside the renderer process.

Exploitation is constrained to the renderer sandbox on initial trigger, but use-after-free primitives in Blink are commonly paired with sandbox-escape bugs to achieve host-level execution. Public exploitation activity recorded in the CISA KEV catalog indicates this vector is already being leveraged against unpatched users.

Root Cause

The root cause is improper object lifetime management in CSS processing logic. Specific style-related allocations are released while other code paths still hold references to them, violating the invariants enforced by Blink's garbage collector and reference-counting model. Crafted HTML and CSS sequences are sufficient to drive the engine into this inconsistent state without any privileged interaction.

Attack Vector

The attack vector is network-based and requires user interaction limited to visiting a malicious or compromised web page. No authentication is needed. Attackers can deliver the exploit through phishing links, malvertising, watering-hole compromises, or embedded iframes on otherwise trusted sites. The vulnerability mechanism is documented in the Chromium Issue Tracker Entry, and a working proof of concept is published at the GitHub CVE-2026-2441 PoC.

Detection Methods for CVE-2026-2441

Indicators of Compromise

  • Chrome renderer process crashes (chrome.exe child processes) with access violation signatures originating from Blink CSS modules
  • Outbound HTTP/HTTPS traffic from browser hosts to newly registered or low-reputation domains hosting HTML payloads with anomalous CSS structures
  • Unexpected child processes spawned by chrome.exe, such as cmd.exe, powershell.exe, or scripting hosts, immediately after browsing activity
  • Browser telemetry showing version strings below 145.0.7632.75 in active sessions

Detection Strategies

  • Inspect endpoint telemetry for Chrome process lineage anomalies and post-exploitation behaviors such as credential access or persistence following a browsing event
  • Correlate web proxy logs with endpoint events to identify users who reached suspicious URLs and subsequently produced abnormal browser behavior
  • Hunt for crash reports referencing CSS style invalidation, layout, or blink::Style* symbols in Windows Error Reporting or crashpad output

Monitoring Recommendations

  • Enforce centralized Chrome version inventory through MDM or configuration management and alert on hosts running builds older than 145.0.7632.75
  • Subscribe SOC pipelines to the CISA KEV feed and the Google Chrome Stable Update advisory for follow-on guidance
  • Increase logging fidelity on browser host segments handling executive, developer, and administrator workflows where targeted exploitation is most likely

How to Mitigate CVE-2026-2441

Immediate Actions Required

  • Update Google Chrome to version 145.0.7632.75 or later on all Windows, macOS, and Linux endpoints
  • Restart browser sessions after deployment to ensure the patched binary is loaded into memory
  • Audit Chromium-based browsers and embedded WebView components that share the Blink rendering engine and apply vendor updates as they become available
  • Prioritize patching for systems exposed to high-risk browsing, including jump hosts, executive workstations, and developer environments

Patch Information

Google released the fix in the Chrome stable channel at version 145.0.7632.75, documented in the Google Chrome Stable Update advisory. The corresponding internal tracking is published in the Chromium Issue Tracker Entry. Confirmation of active exploitation is recorded in the CISA Known Exploited Vulnerability catalog, which mandates federal civilian agencies remediate within the published deadline.

Workarounds

  • Block access to untrusted web content through enterprise web filtering and DNS protection until patching is complete
  • Restrict execution of unsigned binaries and script interpreters launched as children of chrome.exe using application control policies
  • Disable JavaScript on high-risk user groups via Chrome Enterprise policy where business workflows allow, reducing reachability of the CSS code paths
bash
# Verify Chrome version on Linux endpoints across the fleet
google-chrome --version

# Windows: query installed Chrome version via registry
reg query "HKLM\SOFTWARE\Google\Chrome\BLBeacon" /v version

# macOS: read CFBundleShortVersionString from the application bundle
defaults read "/Applications/Google Chrome.app/Contents/Info" CFBundleShortVersionString

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeUse After Free

  • Vendor/TechGoogle Chrome

  • SeverityHIGH

  • CVSS Score8.8

  • EPSS Probability9.46%

  • Known ExploitedYes
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityHigh
  • AvailabilityHigh
  • CISA KEV Information
  • In CISA KEVYes
  • CWE References
  • CWE-416
  • Technical References
  • Google Chrome Stable Update

  • Chromium Issue Tracker Entry

  • GitHub CVE-2026-2441 PoC

  • CISA Known Exploited Vulnerability
  • Related CVEs
  • CVE-2026-9126: Google Chrome DOM Use-After-Free Flaw

  • CVE-2026-9120: Google Chrome WebRTC Use-After-Free Flaw

  • CVE-2026-9118: Google Chrome XR Use-After-Free Flaw

  • CVE-2026-9114: Google Chrome QUIC Use-After-Free Flaw
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English