Google · Google Chrome · CVE-2026-5281
**Name of the Vulnerable Software and Affected Versions**
Google Chrome versions prior to 146.0.7680.178
Chromium-based browsers (affected versions not specified)
**Description**
A use-after-free issue exists in Dawn, the WebGPU layer of Chromium. This flaw allows a remote attacker who has already compromised the renderer process to execute arbitrary code via a specially crafted HTML page. The issue has been confirmed as actively exploited in the wild and is used in multi-stage attack chains to achieve sandbox escape and full host compromise across Windows, macOS, and Linux.
**Recommendations**
Update Google Chrome to version 146.0.7680.177 or 146.0.7680.178.
Apply vendor-specific security updates for other Chromium-based browsers.
As a temporary mitigation, disable WebGPU or hardware acceleration and restrict access to untrusted web content.