đ° Full Story
Google on April 1 released emergency updates for Chrome to fix CVE-2026-5281, a use-after-free vulnerability in Dawn, the WebGPU component, which the company says is being actively exploited in the wild.
The patch is included in Chrome versions 146.0.7680.177/178 for Windows and macOS and 146.0.7680.177 for Linux.
The release addresses 21 security flaws in total and is the fourth Chrome zero-day Google has patched in 2026.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-5281 to its Known Exploited Vulnerabilities (KEV) catalog and ordered federal agencies to remediate the flaw by April 15, 2026.
Google limited technical disclosure pending broad user updates; vendors of other Chromium-based browsers including Microsoft Edge, Vivaldi, Brave and Opera are expected to roll out their own fixes.
Security teams are urged to prioritize deployments and restarts, and organisations should check managed endpoint policies to push the update, since exploitation can allow arbitrary code execution from a compromised renderer process via a crafted web page.








đŹ Commentary