CVE-2026-5284Disclosure(apple / chrome)

MEDIUMCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch apple chrome systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-01); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-01: 2Mentions · 2026-04-02: 1Active Exploitation · 2026-04-02: 1Patch / Workaround · 2026-04-02: 1Technical Details · 2026-04-01: 204-0104-02
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-012
Disclosure2
2026-04-021
Active Exploitation1
Full discourse3 posts
  • しーにゃ♪@公式@Syynya
    Active Exploitation

    【セキュリティ ニュース】「Chrome」にアップデート、脆弱性21件を修正 - 一部で悪用も:Security NEXT https://www.security-next.com/182865 『「Dawn」に関する脆弱性「CVE-2026-5281」「CVE-2026-5284」「CVE-2026-5286」を修正。なかでも「CVE-2026-5281」に関してはすでに悪用が確認されているという』

    Post summary

    The news announces updates fixing 21 Chrome vulnerabilities, including several Dawn CVEs, and notes that CVE-2026-5281 has already been actively exploited.

    00100124
    924 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5284 Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a craft… https://www.cve.org/CVERecord?id=CVE-2026-5284

    Post summary

    The text describes a use‑after‑free flaw in Chrome’s Dawn engine that could allow a remote attacker with renderer process compromise to achieve arbitrary code execution, but no PoC, exploit, patch, or active exploitation details are supplied.

    00000107
    56.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5284 Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium securit... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5284

    Post summary

    CVE-2026-5284 describes a use‑after‑free in the Chrome Dawn engine that could let a compromised renderer process execute arbitrary code through a crafted HTML page. No PoC, exploit, or patch details are offered in the snippet.

    0000041
    4.0K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more