Google released an emergency security update for the Chrome browser to address a high-severity zero-day vulnerability. The flaw is identified as CVE-2026-2441. This vulnerability involves a use-after-free bug within the CSS component.
Remote attackers can execute arbitrary code by crafting malicious HTML pages. Google confirmed that an exploit for this vulnerability exists in the wild. This incident represents the first actively exploited Chrome zero-day addressed by Google in 2026.
The company is withholding specific details regarding attackers or targets to protect the user base during the patch rollout. Security updates are now available for Windows, macOS, and Linux systems. Users must update to the latest versions to mitigate the threat.