CVE-2026-5281

CWE-416Use After Free7 documents7 sources
8.8
CVSS
HIGH
EPSS3.3%(87th)
CISA KEV
CISA Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

NVDgoogle/chrome< 146.0.7680.177
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

🔴Vulnerability Details

2
CVEList
CVE-2026-5281: Use after free in Dawn in Google Chrome prior to 1462026-04-01
VulnCheck
Google Dawn Use-After-Free Vulnerability2026

📋Vendor Advisories

3
CISA
Google Dawn Use-After-Free Vulnerability2026-04-01
Chrome
Chrome: CVE-2026-52812026-03-31
Red Hat
chromium-browser: Use after free in Dawn2026-03-31

🕵️Threat Intelligence

1
Hackernews
New Chrome Zero-Day CVE-2026-5281 Under Active Exploitation — Patch Released2026-04-01