CVE-2026-5286Disclosure(apple / chrome)

MEDIUMCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch apple chrome systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 5 mentions (2026-04-01); latest day: 1
  • 6 total mentions across 2 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-04-01: 5Mentions · 2026-04-02: 1Active Exploitation · 2026-04-01: 1Active Exploitation · 2026-04-02: 1Patch / Workaround · 2026-04-02: 1Technical Details · 2026-04-01: 304-0104-02
Signal classification3 categories
Disclosure
466.7%
Active Exploitation
116.7%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-015
Active Exploitation1Disclosure4
2026-04-021
Patch1
Full discourse6 posts
  • しーにゃ♪@公式@Syynya
    Patch

    【セキュリティ ニュース】「Chrome」にアップデート、脆弱性21件を修正 - 一部で悪用も:Security NEXT https://www.security-next.com/182865 『「Dawn」に関する脆弱性「CVE-2026-5281」「CVE-2026-5284」「CVE-2026-5286」を修正。なかでも「CVE-2026-5281」に関してはすでに悪用が確認されているという』

    Post summary

    The article announces that Chrome has released updates fixing 21 vulnerabilities, some of which are already being exploited. It also highlights that the Dawn vulnerabilities (CVE-2026-5281, CVE-2026-5284, CVE-2026-5286) have been patched, with CVE-2026-5281 confirmed as exploited.

    00100124
    924 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-5286 - High Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) https://www.thehackerwire.com/vulnerability/CVE-2026-5286/ https://t.co/2gI8oUAqzv

    Post summary

    The tweet announces a high‑severity use‑after‑free vulnerability in Google Chrome's Dawn engine that could enable arbitrary code execution through crafted HTML, with no mention of exploitation, PoC, or patches.

    0000038
    163 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Some increased actor activities are shown targeting Google Chrome (CVE-2026-5286) https://vuldb.com/vuln/354609/cti

    Post summary

    The post indicates increased attacker activity targeting CVE-2026-5286 in Google Chrome, but offers no PoC, exploit code, or remedy details.

    0000074
    2.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5286 Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity… https://www.cve.org/CVERecord?id=CVE-2026-5286

    Post summary

    The entry announces CVE‑2026‑5286, a use‑after‑free flaw in Chrome’s Dawn engine that allows remote code execution via crafted HTML, but it does not provide evidence of exploitation, a PoC, or a patch.

    0000092
    56.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5286 Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5286

    Post summary

    CVE‑2026‑5286 is a use‑after‑free vulnerability in Chrome’s Dawn engine allowing arbitrary code execution from crafted HTML, with no PoC, exploit, or active exploitation information provided.

    0000040
    4.0K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    The severity is increased for this new vulnerability affecting Google Chrome (CVE-2026-5286) https://vuldb.com/vuln/354609

    Post summary

    The post announces that CVE-2026-5286, a new vulnerability in Google Chrome, has an increased severity rating, linking to a VULDB page for details, but provides no exploitation, patch, or technical information.

    0000071
    2.1K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more