Google fixed a new Chrome zero-day, tracked as CVE-2026-5281, in the WebGPU Dawn component that is already exploited in the wild.
Google released Chrome updates fixing 21 vulnerabilities, including a new actively exploited zero-day tracked as CVE-2026-5281. The flaw is a use-after-free bug in Dawn, the WebGPU component used for graphics processing.
Due to ongoing exploitation, the company urges users to update their browsers immediately to reduce the risk of attacks.
“Google is aware that an exploit for CVE-2026-5281 exists in the wild.” reads the advisory.
A use-after-free (UAF) bug is a type of memory error where a program continues to use a piece of memory after it has already been freed (released).
EXPLORE MORE
Wanted: Suspect for Multiple Robberies in the 3rd District [VIDEO]
Incident #1:DC# 26-03-012131 On March 26, 2026, at 12:15 AM, the victim,…
The Business of Elegance: How Christine Baranski Built Hollywood’s Most Enduring Empire
Few performers in modern Hollywood command a room quite like Christine Baranski.…
How AI Aids Incident Response: Why Humans Alone Cannot Do IR Efficiently
AI accelerates incident response by correlating alerts and generating reports in minutes,…
Democrat state agrees not to enforce law targeting pro-life pregnancy centers
Pro-life pregnancy centers in Delaware are declaring victory after the state agreed…
U.S. CISA adds a flaw in Soliton Systems K.K FileZen to its Known Exploited Vulnerabilities catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in…
Trump teleprompter operator probed for alleged insider betting
Veteran White House staffer Gabriel Perez is believed to have made more…
Attackers can exploit use-after-free bugs to crash applications, execute malicious code, or
As usual, Google did not reveal technical details of the attacks exploiting this flaw or the type of attackers involved, to give users time to update and prevent others from exploiting it.
CVE-2026-5281 is the fourth Chrome zero-day exploited in attacks in 2026, below the other actively exploited flaws addressed by Google this year:
- February 2026 – CVE-2026-2441 – Use after free in CSS
- March 2026 – CVE-2026-3909 (CVSS score: 8.8) – Out-of-bounds write in the Skia 2D graphics library and CVE-2026-3910 (CVSS score: 8.8) – Flaw in the implementation of the V8 JavaScript/WebAssembly engine
