HIGH

CVE-2026-5281

Google Chrome 2026-04-01 CVSS v3.1
CVSS
8.8
KEV

Description

Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

Summary dbcve.org

Use-after-free vulnerability in Dawn (Google's WebGPU implementation) in Google Chrome prior to version 146.0.7680.178 allows a remote attacker who has already compromised the renderer process to achieve arbitrary code execution by tricking users into visiting crafted HTML pages.

Mitigation

Update Google Chrome to version 146.0.7680.178 or later; organizations should deploy browser updates through their patch management infrastructure and consider restricting WebGPU usage if immediate updating is not feasible.

Weakness (CWE)

CWE-416 Use After Free

EPSS Score

4.94%
Probability of exploitation in next 30 days
91.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE