2026-06-06 is live. RBL, certificate, and uptime monitoring — now in public beta.

News

New Chrome Zero-Day CVE-2026-5281 Under Active Exploitation — Patch Released


Google rolled out a security update for its Chrome browser that remedies 21 flaws, one of which is a zero-day that the company says has been used in real-world attacks.

The most serious issue, tracked as CVE-2026-5281 (CVSS: N/A), is a use-after-free vulnerability located in Dawn – the open-source, cross-platform implementation of the WebGPU standard. According to the entry in the NIST National Vulnerability Database, the bug in Dawn in Chrome versions before 146.0.7680.178 could allow a remote attacker who has already compromised the renderer process to run arbitrary code by crafting a malicious HTML page.

As is typical with actively exploited vulnerabilities, Google has withheld technical specifics about the exploit and attribution. The company said this limited disclosure is intended to give users time to install the patch and to reduce the chance that additional threat actors will copy the attack techniques. Google did confirm it is aware of at least one in-the-wild exploit for CVE-2026-5281.

To protect themselves, users should upgrade Chrome to the patched builds: 146.0.7680.177/178 for Windows and macOS, and 146.0.7680.177 for Linux. To force Chrome to check for updates, open More > Help > About Google Chrome or visit chrome://settings/help, then choose “Relaunch” when the update has downloaded.

Owners of other Chromium-based browsers – including Microsoft Edge, Brave, Opera, and Vivaldi – should monitor their vendors and apply equivalent updates as soon as those fixes are released.

First published on April 2, 2026.
Last updated on July 15, 2026.