CVE-2026-5281Active Exploitation(apple / chrome)

CRITICALCVSS 8.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 94 mentions and remains active

Immediate actions

  • Patch apple chrome systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

10.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-04-15. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-416

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Active exploitation appears in 223 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 283 mentions across 31 observed days

What's happening

  • Active exploitation reported across 223 signals
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 14 signals
  • Patch or workaround mentioned in 197 signals
  • Technical details provided in 154 signals
  • General: 18 classified signals
  • Peaked 30d ago at 94 mentions (2026-04-01); latest day: 2
  • 283 total mentions across 31 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline283 mentions / 31d
024477194Mentions · 2026-04-01: 94Mentions · 2026-04-02: 50Mentions · 2026-04-03: 28Mentions · 2026-04-04: 20Mentions · 2026-04-05: 10Mentions · 2026-04-06: 20Mentions · 2026-04-07: 11Mentions · 2026-04-08: 7Mentions · 2026-04-09: 3Mentions · 2026-04-10: 3Mentions · 2026-04-11: 3Mentions · 2026-04-12: 1Mentions · 2026-04-13: 2Mentions · 2026-04-14: 3Mentions · 2026-04-15: 5Mentions · 2026-04-17: 2Mentions · 2026-04-20: 1Mentions · 2026-04-22: 2Mentions · 2026-04-23: 1Mentions · 2026-04-25: 1Mentions · 2026-04-27: 1Mentions · 2026-04-29: 1Mentions · 2026-04-30: 1Mentions · 2026-05-14: 2Mentions · 2026-05-15: 4Mentions · 2026-06-06: 1Mentions · 2026-06-09: 1Mentions · 2026-07-07: 1Mentions · 2026-08-12: 1Mentions · 2026-09-06: 1Mentions · 2026-09-09: 2PoC Mentioned / Linked · 2026-04-01: 6PoC Mentioned / Linked · 2026-04-02: 1PoC Mentioned / Linked · 2026-04-03: 1PoC Mentioned / Linked · 2026-04-04: 3PoC Mentioned / Linked · 2026-04-05: 1PoC Mentioned / Linked · 2026-04-06: 1PoC Mentioned / Linked · 2026-05-15: 1Exploit Tool / Code · 2026-04-02: 1Exploit Tool / Code · 2026-04-03: 1Exploit Tool / Code · 2026-05-15: 1Active Exploitation · 2026-04-01: 79Active Exploitation · 2026-04-02: 38Active Exploitation · 2026-04-03: 21Active Exploitation · 2026-04-04: 17Active Exploitation · 2026-04-05: 6Active Exploitation · 2026-04-06: 17Active Exploitation · 2026-04-07: 8Active Exploitation · 2026-04-08: 5Active Exploitation · 2026-04-09: 2Active Exploitation · 2026-04-10: 3Active Exploitation · 2026-04-11: 2Active Exploitation · 2026-04-12: 1Active Exploitation · 2026-04-13: 2Active Exploitation · 2026-04-14: 2Active Exploitation · 2026-04-15: 1Active Exploitation · 2026-04-17: 1Active Exploitation · 2026-04-20: 1Active Exploitation · 2026-04-22: 1Active Exploitation · 2026-04-23: 1Active Exploitation · 2026-04-27: 1Active Exploitation · 2026-04-29: 1Active Exploitation · 2026-04-30: 1Active Exploitation · 2026-05-14: 1Active Exploitation · 2026-05-15: 4Active Exploitation · 2026-06-06: 1Active Exploitation · 2026-06-09: 1Active Exploitation · 2026-07-07: 1Active Exploitation · 2026-08-12: 1Active Exploitation · 2026-09-06: 1Active Exploitation · 2026-09-09: 2Patch / Workaround · 2026-04-01: 65Patch / Workaround · 2026-04-02: 38Patch / Workaround · 2026-04-03: 24Patch / Workaround · 2026-04-04: 11Patch / Workaround · 2026-04-05: 5Patch / Workaround · 2026-04-06: 15Patch / Workaround · 2026-04-07: 10Patch / Workaround · 2026-04-08: 5Patch / Workaround · 2026-04-09: 1Patch / Workaround · 2026-04-10: 2Patch / Workaround · 2026-04-11: 1Patch / Workaround · 2026-04-13: 1Patch / Workaround · 2026-04-14: 1Patch / Workaround · 2026-04-15: 4Patch / Workaround · 2026-04-17: 2Patch / Workaround · 2026-04-20: 1Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-04-23: 1Patch / Workaround · 2026-04-27: 1Patch / Workaround · 2026-04-30: 1Patch / Workaround · 2026-05-14: 1Patch / Workaround · 2026-06-06: 1Patch / Workaround · 2026-06-09: 1Patch / Workaround · 2026-08-12: 1Patch / Workaround · 2026-09-06: 1Patch / Workaround · 2026-09-09: 2Technical Details · 2026-04-01: 50Technical Details · 2026-04-02: 30Technical Details · 2026-04-03: 16Technical Details · 2026-04-04: 7Technical Details · 2026-04-05: 4Technical Details · 2026-04-06: 14Technical Details · 2026-04-07: 6Technical Details · 2026-04-08: 5Technical Details · 2026-04-09: 1Technical Details · 2026-04-10: 1Technical Details · 2026-04-11: 1Technical Details · 2026-04-13: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-15: 2Technical Details · 2026-04-17: 2Technical Details · 2026-04-20: 1Technical Details · 2026-04-22: 2Technical Details · 2026-04-23: 1Technical Details · 2026-04-29: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-15: 3Technical Details · 2026-07-07: 1Technical Details · 2026-09-06: 1Technical Details · 2026-09-09: 204-0104-0404-0704-1004-1304-1704-2304-2905-1507-0709-09
Signal classification4 categories
Active Exploitation
19870.0%
Patch
5318.7%
General
186.4%
Disclosure
144.9%
Referenced assets114 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-0194
Active Exploitation71Disclosure7General4Patch12
2026-04-0250
Active Exploitation32General3Patch15
2026-04-0328
Active Exploitation18Disclosure1General2Patch7
2026-04-0420
Active Exploitation14Disclosure2Patch4
2026-04-0510
Active Exploitation6General2Patch2
2026-04-0620
Active Exploitation17Disclosure2Patch1
2026-04-0711
Active Exploitation8General1Patch2
2026-04-087
Active Exploitation3Disclosure1Patch3
2026-04-093
Active Exploitation2General1
2026-04-103
Active Exploitation3
2026-04-113
Active Exploitation2General1
2026-04-121
Active Exploitation1
2026-04-132
Active Exploitation2
2026-04-143
Active Exploitation2Patch1
2026-04-155
Active Exploitation1General1Patch3
2026-04-172
Active Exploitation1Patch1
2026-04-201
Active Exploitation1
2026-04-222
Active Exploitation1General1
2026-04-231
Active Exploitation1
2026-04-251
General1
2026-04-271
Patch1
2026-04-291
Active Exploitation1
2026-04-301
Active Exploitation1
2026-05-142
General1Patch1
2026-05-154
Active Exploitation3Disclosure1
2026-06-061
Active Exploitation1
2026-06-091
Active Exploitation1
2026-07-071
Active Exploitation1
2026-08-121
Active Exploitation1
2026-09-061
Active Exploitation1
2026-09-092
Active Exploitation2
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    🛑 Chrome 0-day Warning! Tracked as CVE-2026-5281, this WebGPU (Dawn) use-after-free bug allows code execution via a crafted page if the renderer is compromised. It’s the 4th exploited Chrome browser zero-day in 2026. 🔗 Read → https://thehackernews.com/2026/04/new-chrome-zero-day-cve-2026-5281-under.html

    Post summary

    CVE‑2026‑5281 is a use‑after‑free flaw in Chrome’s WebGPU engine that enables code execution via crafted pages, and it is reported as actively exploited, though no PoC or patch has been disclosed.

    161401340310659.2K
    1.6M followersView on X
  • H4x0r.DZ 🇰🇵@h4x0r_dz
    General

    Who is Exploiting Chrome 0-day CVE-2026-5281?

    Post summary

    The post merely poses a question about exploitation of CVE-2026-5281 without providing any supporting details, confirmation of active attacks, or mitigation information.

    12612185931.5K
    81.1K followersView on X
  • Zero Day Engineering@zerodayalpha
    Active Exploitation

    ⚡️0-Day Alert: Google Chrome GPU Remote to Elevation of Privilege exploit in the wild CVE-2026-5281: Dawn Server Use-after-free due to improper clearing of callbacks upon DeviceInfo object destruction 🔒Issue: https://issues.chromium.org/issues/491518608 The bug is interesting: a partial EoP that can potentially be triggered remotely via WebGPU API calls. Normally this chain of impact requires at least 2-3 separate bugs. The fact that it was cherry-picked to M146 confirms high-to-critical impact. Patched in 146.0.7680.177/178 for Windows/Mac and 146.0.7680.177 for Linux on 31st March

    Post summary

    CVE‑2026‑5281, a use‑after‑free bug in Chrome’s GPU/WebGPU stack, is being actively exploited in the wild and has prompted patch releases in Chrome 146, with details documented on Chromium’s issue tracker.

    323015710013.7K
    11.0K followersView on X
  • Cybernews@Cybernews
    Active Exploitation

    Just days after rolling out a high-risk security update for Chrome, Google is already warning of a second threat, a new zero-day exploit (CVE-2026-5281) actively being used by hackers against Chrome's 3.5 billion users right now. Google has already started rolling out a fix for this vulnerability.However, it could take days or weeks to reach your device automatically. You don't have to wait though, you can manually update Chrome right now. Source: Forbes Subscribe to our newsletter: https://cnews.link/newsletter-7/

    Post summary

    CVE-2026-5281 is a zero‑day actively exploited against Chrome users worldwide, and Google is already distributing a patch that can be applied manually.

    329275154.3K
    71.6K followersView on X
  • xvonfers@xvonfers
    Patch

    (CVE-2026-5281)[491518608][dawn][wire]UAF, exploited ITW https://dawn-review.googlesource.com/c/dawn/+/297136 https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_31.html

    Post summary

    CVE‑2026‑5281 is a use‑after‑free flaw that has been exploited in the wild, and Google has already issued a patch in the 2026.03 stable channel.

    27046197.3K
    5.0K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added Google Dawn use-after-free vulnerability CVE-2026-5281 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity #InfoSec https://t.co/Z2Bz7tDLQR

    Post summary

    The DHS announcement that CVE-2026-5281, a use‑after‑free flaw in Google Dawn, has been added to its Known Exploited Vulnerabilities Catalog signals that the vulnerability is actively being exploited in the wild.

    217239108.9K
    298.7K followersView on X
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ Chrome Zero-Day CVE-2026-5281: A Use-After-Free in Dawn's WebGPU Layer https://darkwebinformer.com/chrome-zero-day-cve-2026-5281-a-use-after-free-in-dawns-webgpu-layer/

    Post summary

    The post announces CVE‑2026‑5281, a use‑after‑free vulnerability in Chrome’s Dawn WebGPU layer, highlighting the discovery but providing no exploitation or mitigation details.

    0411944.5K
    218.4K followersView on X
  • Blue Team News@blueteamsec1
    Active Exploitation

    New Chrome Zero-Day CVE-2026-5281 Under Active Exploitation — Patch Released http://dlvr.it/TSJnPC #Chrome #Security #CyberSecurity #ZeroDay #Vulnerability https://t.co/cXajQLNlPa

    Post summary

    CVE‑2026‑5281 is a Chrome zero‑day that is currently being actively exploited in the wild; a patch has been released and is available via the provided link.

    0311844.5K
    56.4K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    Google Chromeのゼロデイ脆弱性が緊急修正。CVE-2026-5281はDawnのWebGPUにおける解放後メモリ使用。今年のChromeゼロデイは4件目。 https://darkwebinformer.com/chrome-zero-day-cve-2026-5281-a-use-after-free-in-dawns-webgpu-layer/

    Post summary

    Google Chrome has issued an emergency patch for CVE-2026-5281, a use‑after‑free bug in the Dawn WebGPU layer.

    1511312.4K
    7.6K followersView on X
  • GovCERT.CZ@GOVCERT_CZ
    Active Exploitation

    🚨 Upozorňujeme na aktivně zneužívanou zranitelnost v Google Chrone, CVE-2026-5281. Byla identifikována vysoce závažná zranitelnost typu use-after-free v komponentě Dawn, což je open‑source implementace standardu WebGPU. Chyba umožňuje vzdálenému útočníkovi, který předem kompromitoval renderer proces, spustit libovolný kód prostřednictvím speciálně vytvořené HTML stránky. Zranitelnost je aktivně zneužívána v reálném prostředí. Problém postihuje verze Google Chrome před 146.0.7680.178. Google neposkytl další detaily o způsobu zneužití, což je běžná praxe, dokud většina uživatelů neaplikuje dostupnou opravu. Pro Windows a macOS je dostupná oprava ve verzi 146.0.7680.177/178, pro Linux ve verzi 146.0.7680.177. Ostatní prohlížeče založené na Chromium (Microsoft Edge, Brave, Opera, Vivaldi) musí rovněž co nejdříve aplikovat dostupné aktualizace. 📌 Doporučujeme aktualizovat na nejnovější verzi.

    Post summary

    A use‑after‑free vulnerability (CVE‑2026‑5281) in Chrome’s Dawn WebGPU component is actively being exploited via specially crafted HTML pages; users on any platform should promptly apply the available patch.

    0401231.3K
    4.2K followersView on X
  • Claudio@sonoclaudio
    Disclosure

    Nuova vulnerabilità zero-day CVE-2026-5281 Aggiornate #Brave, #Chrome, etc. browser Chromium based. https://thehackernews.com/2026/04/new-chrome-zero-day-cve-2026-5281-under.html

    Post summary

    A newly discovered zero‑day vulnerability (CVE‑2026‑5281) affecting Chromium‑based browsers has been reported, and users are urged to update their browsers.

    050130558
    3.5K followersView on X
  • Team D4rkn3ttz@Team_D4rkn3ttz
    General

    IR/CERT Morning Brief Today’s priorities were: Chrome/WebGPU-related CVE-2026-5281 / Google Dawn KEV-linked signals, a CERT-UA impersonation campaign spreading AGEWHEEZE, and Axios npm supply-chain follow-up. Cisco and Nissan items remained in the “claim / monitor” bucket, while Dark Web noise was intentionally deprioritized. #cybersecurity #threatintel #IR #CERT

    Post summary

    The brief identifies CVE‑2026‑5281 as a priority item but offers no technical, exploit, or patch details.

    51041408
    320 followersView on X
  • HostingTech@HostingTechNet
    Patch

    Google Chrome patches CVE-2026-5281 https://hostingtech.net/google-chrome-patches-cve-2026-5281/ via @HostingTech https://t.co/s4UMivVDy3

    Post summary

    The tweet announces that Google Chrome has released patches for CVE‑2026‑5281 and directs readers to a link for further details.

    02080149
    183 followersView on X
  • IT-Connect.fr@ITConnect_fr
    Patch

    🛑 Patch Google Chrome La 4ème faille zero-day de l'année 2026 a été patchée dans le navigateur de Google. -> CVE-2026-5281 Le récap 👇 - https://www.it-connect.fr/google-corrige-en-urgence-la-4eme-faille-zero-day-de-chrome-en-2026/ #Google #GoogleChrome #Web #infosec https://t.co/lQCKGbeRe8

    Post summary

    The CVE‑2026‑5281 zero‑day vulnerability in Google Chrome has been fixed, with a vendor patch referenced, but no exploit details or active exploitation are mentioned.

    03061584
    11.4K followersView on X
  • Securízame@Securizame
    Active Exploitation

    Google parchea un zero-day de Chrome en WebGPU (CVE-2026-5281) que ya se está explotando https://unaaldia.hispasec.com/2026/04/google-parchea-un-zero-day-de-chrome-en-webgpu-cve-2026-5281-que-ya-se-esta-explotando.html #Internet #Noticia #Tecnología #CiberSeguridad #Web vía @unaaldia https://t.co/twQ1w9qRMH

    Post summary

    Google has released a patch for a Chrome WebGPU zero‑day (CVE‑2026‑5281) that is already being actively exploited in the wild.

    02061360
    15.4K followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    🔥 CVE-2026-5281: Chrome zero-day WebGPU UAF (Dawn), 4th in 2026. Update to 134.0.6998.177! https://thehackernews.com/2026/04/new-chrome-zero-day-cve-2026-5281-under.html

    Post summary

    CVE‑2026‑5281 is a newly disclosed Chrome zero‑day involving a WebGPU use‑after‑free; users are advised to patch to version 134.0.6998.177.

    1205070
    1.4K followersView on X
  • AI Detective@AI_DetectiveXYZ
    Active Exploitation

    Google pushed an emergency Chrome patch this week for CVE-2026-5281 -- an actively exploited zero-day in the Dawn WebGPU component. Attackers were already using it in the wild before the fix shipped. @CISAgov tracks and catalogs vulnerabilities like this.

    Post summary

    CVE‑2026‑5281 is an actively exploited zero‑day in Chrome’s Dawn WebGPU component, prompting Google to issue an emergency patch before attackers could fully exploit it.

    11040115
    33 followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    📌 جوجل تصدر تحديثاً لمعالجة ثغرة أمنية تستغل بنشاط في Chrome أصدرت Google تحديثًا لمتصفح Chrome لمعالجة ثغرة أمنية (CVE-2026-5281) يجري استغلالها بنشاط. تتواجد هذه الثغرة في Dawn، وهي تطبيق مفتوح المصدر ومتعدد المنصات لـ WebGPU داخل Chrome. يُمكن للمهاجمين استغلال هذه الثغرة لتنفيذ تعليمات برمجية عن بعد أو تجاوز الضوابط الأمنية. يُنصح جميع مستخدمي Chrome بتحديث متصفحاتهم فورًا للحماية من هذه التهديدات. 🔗 للمزيد: https://www.security.nl/posting/930780/Google+rolt+update+uit+voor+actief+aangevallen+beveiligingslek+in+Chrome?channel=rss

    Post summary

    Google released a Chrome update to patch CVE-2026-5281, a vulnerability in Dawn that is actively exploited, enabling remote code execution. Users are advised to update immediately.

    00050822
    245 followersView on X
  • QuanChain@Quan_Chain
    General

    Chrome's zero-day problem isn't a browser problem. It's a patch cadence problem. CVE-2026-5281 is the 21st vulnerability in this single Chrome update. Twenty-one. Each one is a window between discovery and deployment where systems running unpatched software are exposed. That window is the real attack surface. QuanChain's LQCp/h Oracle works on the same principle in reverse: it monitors global quantum capability in real-time across 7 threat levels, and DTQPE escalates security automatically before a window opens, not after exploitation is confirmed. The browser security model has trained users to wait for a patch. Is that model still acceptable when the threat isn't a use-after-free bug but a cryptographic assumption that can't be patched retroactively?

    Post summary

    The post comments on CVE‑2026‑5281 as an example of Chrome’s patch‑cadence problem, noting exposure windows before patches and questioning the reliance on patching for cryptographic‑assumption vulnerabilities.

    10040164
    92.2K followersView on X
  • CYBER RANGE LABS@cyberrangelabs
    Active Exploitation

    CVE-2026-5281 — a use-after-free vulnerability in Chrome's Dawn WebGPU engine — was actively being exploited in the wild before the patch dropped. CISA has already ordered all US federal agencies to update by April 15th. 4 zero-days in 100 days. That's one every 25 days.

    Post summary

    CVE‑2026‑5281 is a use‑after‑free flaw in Chrome’s Dawn WebGPU engine that was actively exploited in the wild and has since been patched, with CISA requiring federal agencies to update by April 15.

    1003082
    20 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more