Overview
What is CVE-2026-5281?
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Google Dawn Use-After-Free Vulnerability
CISA lists CVE-2026-5281 in its Known Exploited Vulnerabilities catalog, which means exploitation has been observed. The entry applies to Google Dawn.
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)