
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2321 is a use-after-free vulnerability in the Ozone component of Google Chrome that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. The attacker must convince a user to engage in specific UI gestures to trigger the flaw. It affects all versions of Google Chrome prior to 145.0.7632.45 on Windows, Mac, and Linux. The vulnerability was reported internally by Google on 2025-11-18 and patched on February 10, 2026, with public disclosure on February 11, 2026. It carries a CVSS v3.1 base score of 8.8 (High) and is rated Medium severity by Chromium's internal security scale (Chrome Releases, Feedly).
The vulnerability is classified as CWE-416 (Use After Free), occurring within Chrome's Ozone platform abstraction layer, which handles windowing and UI input on Linux-based systems. A use-after-free condition arises when memory that has been freed is subsequently accessed, potentially allowing an attacker to control the contents of that memory region and redirect program execution. Exploitation requires delivery via a crafted HTML page and user interaction in the form of specific UI gestures, making it a network-delivered, user-interaction-required attack. No public technical write-up or proof-of-concept code has been identified at this time (Chrome Releases, Feedly).
Successful exploitation could lead to heap corruption, with potential consequences including arbitrary code execution or denial of service within the context of the Chrome browser process. Given Chrome's sandboxing architecture, a full system compromise would typically require chaining this vulnerability with a sandbox escape; however, code execution within the renderer or browser process could still expose sensitive user data, session tokens, and browsing history. The confidentiality, integrity, and availability impacts are all rated High (Feedly).
Google has released a patch in Chrome 145.0.7632.45 (Linux) and 145.0.7632.45/46 (Windows/Mac), which addresses this and 10 other security vulnerabilities. Users and administrators should update all Chrome installations to version 145.0.7632.45 or later immediately. As a general precaution, users should avoid visiting untrusted websites and be wary of pages that prompt unusual UI interactions. Downstream distributions including Debian, openSUSE, Fedora, and ChromeOS have also released updated Chromium packages incorporating this fix (Chrome Releases).
The Chrome 145 security update received coverage from several cybersecurity news outlets including GBHackers, CyberSecurityNews, and CyberPress, which highlighted the 11 security fixes included in the release. Social media accounts such as TheHackerWire shared the update on Bluesky and Mastodon. Security vendors including Tenable (Nessus) and Qualys published detection plugins for the vulnerability shortly after disclosure. Palo Alto Networks also issued an advisory (PAN-SA-2026-0003) as part of their monthly Chromium vulnerability update for March 2026 (Chrome Releases, Palo Alto Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."