Chrome gets emergency fix for the first 2026 zero-day exploited in the wild

TL;DR Summary
Google released emergency Chrome updates to fix CVE-2026-2441—a use-after-free in CSSFontFeatureValuesMap exploited in the wild—marking Chrome’s first zero-day patch of 2026; the fix has been backported across commits and is rolling out to Windows, macOS (145.0.7632.75/76), and Linux (144.0.7559.75), with a note that related issues remain addressed in bug 48393607. Users should update Chrome or enable auto-update.
- Google patches first Chrome zero-day exploited in attacks this year BleepingComputer
- New Chrome Zero-Day (CVE-2026-2441) Under Active Attack — Patch Released The Hacker News
- Google Patches First Actively Exploited Chrome Zero-Day of 2026 SecurityWeek
- Exploit available for new Chrome zero-day vulnerability, says Google csoonline.com
- Google fixes exploited Chrome CSS zero-day theregister.com
Reading Insights
Total Reads
1
Unique Readers
9
Time Saved
3 min
vs 4 min read
Condensed
91%
662 → 57 words
Want the full story? Read the original article
Read on BleepingComputer