
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2313 is a use-after-free vulnerability in the CSS processing component of Google Chrome, classified as High severity. It affects all versions of Google Chrome prior to 145.0.7632.45 on Windows, Mac, and Linux, as well as Microsoft Edge (Chromium-based). The vulnerability was reported by Han Zheng (HexHive), Wenhao Fang (University of St. Andrews), and Qinying Wang (HexHive) on 2025-12-09, and patched on February 10, 2026 with the Chrome 145 stable channel release. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Release, Microsoft MSRC).
The vulnerability is classified as CWE-416 (Use After Free), occurring within Chrome's CSS processing engine. A use-after-free condition arises when memory that has been freed is subsequently accessed, potentially allowing an attacker to control the contents of that memory region and redirect program execution. Exploitation requires a victim to visit a specially crafted HTML page, which triggers the CSS parsing logic to access freed heap memory, potentially leading to heap corruption. No public proof-of-concept or detailed technical write-up has been disclosed as of the time of reporting (Chrome Release, Feedly).
Successful exploitation of CVE-2026-2313 could allow a remote attacker to achieve arbitrary code execution with the privileges of the user running Chrome, by inducing heap corruption through a malicious HTML page. This could result in high confidentiality, integrity, and availability impacts — including theft of sensitive browser data (cookies, credentials, saved passwords), installation of malware, or full compromise of the affected user's session. The vulnerability affects all major desktop platforms (Windows, Mac, Linux) and Chromium-based Microsoft Edge, broadening the potential attack surface (Chrome Release, Feedly).
cmd.exe, powershell.exe, bash, curl, wget); Chrome processes exhibiting abnormal CPU or memory usage.Google has released Chrome 145.0.7632.45 (Linux) and 145.0.7632.45/46 (Windows/Mac) to address this vulnerability; users should update immediately via Chrome's built-in update mechanism or by downloading from the official Chrome website. Microsoft has also released a corresponding update for Microsoft Edge (Chromium-based), tracked under the same CVE. As a temporary workaround, organizations can restrict access to untrusted or unknown websites via browser policy and educate users to avoid clicking suspicious links. Downstream distributions (Debian, Fedora, openSUSE) have also released updated Chromium packages (Chrome Release, Microsoft MSRC).
The Chrome 145 security update received broad coverage from security news outlets including GBHackers, CyberSecurityNews, SecurityOnline, and CyberPress, which highlighted the three High-severity fixes (CVE-2026-2313, CVE-2026-2314, CVE-2026-2315) as notable for their potential code execution impact. Check Point Research included the vulnerability in their February 16, 2026 weekly threat intelligence report. Community discussion on Reddit (r/pwnhub) noted the patch as part of Chrome 145's 11-vulnerability fix batch. The $8,000 bug bounty awarded to the HexHive/University of St. Andrews research team was noted as reflecting the vulnerability's assessed severity (Chrome Release, SecurityOnline).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."