Skip to content

Google Patches Fourth Chrome Zero-Day of 2026 — CVE-2026-5281 Use-After-Free in WebGPU

Google has patched CVE-2026-5281, a use-after-free vulnerability in Chrome's Dawn WebGPU implementation that is being actively exploited in the wild. This is the fourth Chrome zero-day exploited in attacks in 2026. CISA added it to the KEV catalogue on 1 April with a deadline of 15 April for federal agencies. Update to Chrome 146.0.7680.177/178.

Article security-operations

Google has released an emergency Chrome update addressing CVE-2026-5281, a use-after-free vulnerability in Dawn — Chrome’s open-source cross-platform WebGPU implementation — that has been exploited in the wild. This is the fourth Chrome zero-day to be actively weaponised in 2026, continuing an accelerating pattern of browser exploitation that security teams cannot afford to treat as routine.

The Vulnerability

CVE-2026-5281 is a use-after-free flaw in Dawn, the component responsible for Chrome’s WebGPU API. Use-after-free vulnerabilities occur when a programme continues to use memory after it has been freed, allowing an attacker to corrupt heap memory and achieve arbitrary code execution in the context of the renderer process. WebGPU, designed to expose GPU capabilities to web applications, is a complex, high-performance API with a large attack surface — the kind of code that frequently contains memory safety issues.

Google’s advisory acknowledges that an exploit for CVE-2026-5281 exists in the wild, though attribution and specific attack vectors have not been publicly disclosed. The full release addressed 21 vulnerabilities in total.

The 2026 Chrome Zero-Day Tracker

This is now the fourth actively exploited Chrome zero-day of the year:

  • January 2026 — No exploited zero-day published
  • February 2026 — CVE-2026-2441: Use-after-free in CSS
  • March 2026 — CVE-2026-3909 (CVSS 8.8): Out-of-bounds write in Skia 2D graphics
  • March 2026 — CVE-2026-3910 (CVSS 8.8): Flaw in V8 JavaScript/WebAssembly engine
  • April 2026 — CVE-2026-5281: Use-after-free in Dawn/WebGPU (this disclosure)

The pace — four exploited zero-days in the first quarter of the year — reflects sustained adversary investment in browser exploitation, whether for intelligence collection, initial access, or watering-hole attack campaigns.

CISA KEV Deadline

CISA added CVE-2026-5281 to the Known Exploited Vulnerabilities catalogue on 1 April 2026, setting 15 April 2026 as the remediation deadline for Federal Civilian Executive Branch agencies. That deadline falls today, meaning federal environments that have not yet updated are now overdue.

Fixed Versions

Google has patched the vulnerability in:

  • Chrome 146.0.7680.177/178 for Windows and macOS
  • Chrome 146.0.7680.177 for Linux

Users on the Stable channel should receive the update automatically. Enterprise environments using Chrome through managed policies should verify auto-update is enabled and confirm the deployed version matches the patched release.

  1. Verify Chrome is updated to 146.0.7680.177 or later across all managed endpoints. Navigate to chrome://version/ or use your endpoint management tool to confirm.
  2. Enable Chrome auto-update in enterprise policy if it has been disabled — manual patching processes create unacceptable lag windows when zero-days are in active exploitation.
  3. Consider Chromium-based browser estate scope: Microsoft Edge and other Chromium-based browsers share WebGPU rendering components. Check for vendor patches for those products as well.
  4. Review web proxy and DNS logs for indicators of drive-by download campaigns or watering-hole infrastructure targeting browsers with unpatched Dawn vulnerabilities.
  5. For high-risk users (executives, finance teams, legal), enforce browser updates as a P1 patching item and consider temporarily restricting access to WebGPU-intensive sites if the business context permits.

The frequency of Chrome zero-days in 2026 argues for treating browser patching as infrastructure patching rather than endpoint hygiene — the same urgency that would apply to a network appliance vulnerability should apply here.

Share this article

Related Intelligence

🛡️ SecOps

Google Chrome Zero-Day CVE-2026-11645: V8 Out-of-Bounds Write Actively Exploited Before Patch

Google has released Chrome 149.0.7762.95 patching CVE-2026-11645, an out-of-bounds write in the V8 JavaScript engine that was actively exploited before disclosure. CISA has added the flaw to the Known Exploited Vulnerabilities catalogue. All users and enterprise deployments should update immediately — CISA's federal deadline is 30 June.

#chrome +8
🛡️ SecOps

Android June 2026 Security Update: Zero-Day CVE-2025-48595 Patched Alongside 124 Vulnerabilities

Google's June 2026 Android Security Bulletin patches 124 vulnerabilities including CVE-2025-48595, an integer overflow in the Android Framework with confirmed limited exploitation consistent with nation-state spyware deployment. Enterprise Android fleets should prioritise this update given the zero-day's targeted exploitation pattern.

#android +7
🛡️ SecOps

CISA Adds Seven to KEV Catalogue — Including Two Active Microsoft Defender Zero-Days Patched via Silent Engine Update

CISA's 20 May Known Exploited Vulnerabilities batch included CVE-2026-41091 (Microsoft Defender for Endpoint EoP, CVSS 7.8) and CVE-2026-45498 (Microsoft Defender DoS, CVSS 4.0), both patched via a silent Defender engine update pushed on 19 May. The batch also included five legacy Windows and Adobe vulnerabilities from 2008–2010 indicating re-exploitation of outdated systems in active campaigns.

#microsoft-defender +6