ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Google fixes Chrome zero-day with in-the-wild exploit (CVE-2026-5281)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-4675
+1 in the same advisory: …4676
Heap buffer overflow in WebGL in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

Heap buffer overflow in WebGL in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

NVD description · AI analysis pending
8.8<1%
  • google chrome
CVE-2026-5281
Use-After-Free in Google Chrome's Dawn (WebGPU) Component Enables Arbitrary Code Execution

CVE-2026-5281 is a use-after-free vulnerability in Dawn, the WebGPU implementation in Google Chrome, that Google patched in Chrome 146.0.7680.178. It is triggered when a remote attacker serves a crafted HTML page and can leverage it after having already compromised the Chrome renderer process, escalating to arbitrary code execution beyond the initial foothold. Because the flaw requires a compromised renderer as a starting point, it is typically chained with another bug (such as a renderer-exploiting issue) to break out to arbitrary code execution with real impact on confidentiality, integrity, and availability. Any user or organization running Google Chrome on a version prior to 146.0.7680.178 is affected. The flaw is confirmed as exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-04-01, and its EPSS score of 4.9% (92nd percentile) indicates a meaningful near-term exploitation probability.

Do: Update Google Chrome to 146.0.7680.178 or later on all endpoints immediately, prioritizing internet-facing and high-risk user populations given the KEV listing. Because the bug requires a compromised renderer, treat it as part of a chained attack and ensure other browser-layer defenses (renderer sandbox enabled, prompt patching of related renderer bugs) are in place; federal agencies must follow BOD 22-01 remediation timelines or discontinue use if patching is unavailable.

8.85% KEV
  • Google Chrome prior to 146.0.7680.178
  • Google Dawn (WebGPU implementation bundled in Chrome) as shipped in Chrome prior to 146.0.7680.178
masseffectively all Chrome users on unpatched builds
CVE-2026-5284
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via

Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

NVD description · AI analysis pending
7.5<1%
  • google chrome

Indicators of compromiseAll →

TypeIndicatorContext
md586ac1f1587b71893ed2ad792cd7dde32.” CVE-2026-5281 was flagged by a pseudonymous bug hunter ( 86ac1f1587b71893ed2ad792cd7dde32 ), who previously reported two vulnerabilities that have be
Full article287 words · extracted from helpnetsecurity.com · click to collapse

Google has fixed 21 vulnerabilities affecting its popular Chrome browser, among them a zero-day (CVE-2026-5281) with an in-the-wild exploit.

About CVE-2026-5281

As per usual, information about the fixed zero-day is limited, and there’s no details about the exploit (or how/if it’s being used by attackers).

CVE-2026-5281’s official description says it’s a use-after-free (UAF) vulnerability in Dawn, an open-source and cross-platform implementation of the WebGPU standard that’s used in Chromium and Chromium-based browsers.

The vulnerability affects Chrome versions before v146.0.7680.177/178 for Windows/Mac, and before v146.0.7680.177 for Linux.

It allows “a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page.”

CVE-2026-5281 was flagged by a pseudonymous bug hunter (86ac1f1587b71893ed2ad792cd7dde32), who previously reported two vulnerabilities that have been fixed in the Chrome update released on March 23, 2026: a heap buffer overflow in WebGL (CVE-2026-4675) and another use-after-free bug in Dawn (CVE-2026-4676).

The bug hunter also reported a third use-after-free in Dawn (CVE-2026-5284) that has been fixed this time around.

CVE-2026-5281 fixes for other Chromium-based browsers

Chrome users that rely on manual updating are advised to get on it. Those who have opted for auto-updating option will received it automatically and need only to restart the browser once the update becomes available.

Chromium-based Vivaldi has already pushed out the fix, while Microsoft is working on releasing one for its Edge browser.

Earlier this month, Google announced that starting in September 2026, the beta and stable versions of Chrome will be released once every two weeks, to minimize disruption and to deliver new features, improvements and bug fixes faster.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/04/01/google-chrome-zero-day-cve-2026-5281/