Fixing and finding

[Jump to remediation plan](#remediation)

CVE ID

# CVE-2026-5281

Published 2026-04-01

Updated 2 months ago

Vendor/s

Google

Product/s

Dawn

Version/s

\* > 146.0.7680.177

KEV Status

Active Exploitation

Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.

CVSS Score (v3.1)

8.8

/ 10

High

Severity Details

Base score

8.8 High

Attack vector

Network

Attack complexity

Low

Privileges required

None

User interaction

Required

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Table of Contents

[Description ](#description)[Why this matters ](#why-this-matters)[CPE ](#cpe)[Related weakness (CWE) ](#cwe)[Remediation plan ](#remediation)[Detection Guidance ](#detection-guidance)[References ](#references)[Sources](#sources)

[Description ](#description)[Why this matters ](#why-this-matters)[CPE ](#cpe)[Related weakness (CWE) ](#cwe)[Remediation plan ](#remediation)[Detection Guidance ](#detection-guidance)[References ](#references)[Sources](#sources)

## Description

CVE-2026-5281 is a high-severity use-after-free vulnerability in Google Chrome's Dawn component, allowing RCE. Affects versions prior to 146.0.7680.178.

## Why this matters

CVE-2026-5281 is a critical security concern because it is actively being exploited in the wild, as evidenced by its inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog. With a CVSS score of 8.8, this use-after-free vulnerability in the Dawn component of Google Chrome allows a remote attacker who has already compromised a renderer process to escalate privileges and execute arbitrary code. This chain of exploitation can lead to full system compromise simply by a user visiting a malicious HTML page. Security teams must prioritize this update due to the active threat landscape and the high potential for data exfiltration.

## CPE

Google

| Product       | Version Start | Version End (excl.) | Status     |
| ------------- | ------------- | ------------------- | ---------- |
| chrome        | \*            | 146.0.7680.177      | vulnerable |
| macos         | -             | -                   | unaffected |
| linux\_kernel | -             | -                   | unaffected |
| windows       | -             | -                   | unaffected |

## Related weakness (CWE)

CWE-416

## Remediation plan

1

### Apply official patches

Update Google Chrome to version 146.0.7680.178 or higher immediately to address the use-after-free flaw in the Dawn component.

2

### Update affected systems

Verify that all desktop installations across Windows, macOS, and Linux are running a version later than 146.0.7680.177 to ensure the patch is applied.

3

### Restrict access

Implement robust browser sandboxing and consider web filtering to block access to known malicious domains that may host exploit code targeting the renderer process.

4

### Monitor for exploitation

Track frequent or unexplained crashes of the Chrome renderer process and monitor for unusual child processes or unauthorized file system modifications originating from the browser.

## Detection Guidance

Detection should focus on identifying anomalous behavior within the Chrome renderer process. Look for repeated crashes in the Dawn/WebGPU modules or unexpected memory access patterns. Security teams should monitor EDR logs for Chrome processes spawning shells or executing suspicious commands. Additionally, inspect network traffic for connections to suspicious external IPs following a browser crash, which may indicate a successful stage-two payload delivery.

## References

[https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop\_31.html Vendor Advisory ](https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_31.html)[https://issues.chromium.org/issues/491518608 Issue Tracking Permissions Required ](https://issues.chromium.org/issues/491518608)[https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field\_cve=CVE-2026-5281 US Government Resource](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-5281)

## Sources

NIST National Vulnerability Database (NVD)

CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management

[Get a demo](https://www.upguard.com/contact-sales)

[Free trial](https://www.upguard.com/demo)
