Google patches actively exploited Chrome zero-day
Google has issued an out-of-band update to fix a high-severity Chrome vulnerability that is being exploited in the wild. The flaw sits in the browser's CSS component, is designated CVE-2026-2441 and carries a CVSS score of 8.8. If exploited, it may allow an attacker to execute arbitrary code within the browser sandbox when a user is lured into visiting a malicious page. Affected versions are Chrome for Windows and Mac prior to 145.0.7632.75/76 and Chrome for Linux prior to 144.0.7559.7. Updates are also available for most Chromium-based browsers, including Opera and Vivaldi.
What this means for your organisation
The browser is in practice the surface where most employees reach business systems, email and cloud services. A flaw triggered by visiting a page requires nothing from the user beyond a click, and it is already being used in attacks. Exposure is therefore decided by how quickly the update reaches your fleet, not by whether you have a patching policy on paper.
Berigo recommends
- Force a browser restart across all clients, since a downloaded Chrome update only takes effect after a relaunch.
- Check your endpoint management data for how many clients still run versions below 145.0.7632.75.
- Include Chromium-based alternatives such as Opera, Vivaldi and Edge in the same round.
- Set an internal deadline for rolling out browser fixes for actively exploited flaws, measured in days rather than weeks.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch