socradar.io 4/2/2026, 3:05:44 PM · via preferred

CVE-2026-5281: Chrome WebGPU Zero-Day Exploited In The Wild

CVE-2026-5281: Chrome WebGPU Zero-Day Exploited In The Wild

Google patched CVE-2026-5281, a high-severity use-after-free vulnerability in Dawn, Chromium’s WebGPU implementation, and it has confirmed exploitation in the wild. The NVD wording outlines that a remote attacker who had already compromised the renderer process could execute arbitrary code via a crafted HTML page. Chrome fixed the flaw in stable desktop…

First seen 2026-04-01T13:50:49.621Z · Last seen 2026-04-02T15:05:44.153Z

CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Available

GOOGLE patched CVE-2026-5281, a high-severity use-after-free vulnerability in Dawn, Chromium’s WebGPU implementation, and it has confirmed exploitation in the wild. The NVD wording outlines that a remote attacker who had already compromised the renderer process could execute arbitrary code via a crafted HTML page. Chrome fixed the flaw in stable desktop builds released on 31 March 2026, with Windows and macOS versions 146.0.7680.177/178 and Linux 146.0.7680.177.

The CISA KEV catalogue added CVE-2026-5281 on 1 April 2026, with a remediation due date for federal agencies of 15 April 2026. Potentially, other Chromium-based browsers may be affected until upstream fixes are included in their builds. Public technical details remain limited, and Google’s release notes describe the flaw only as a use-after-free in Dawn, with additional details restricted by the Chromium project.

View Primary Source Via socradar.io

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline