Description
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
In plain language
AI Act nowCVE-2026-5281 is a serious Chrome bug that lets an attacker who already compromised the browser’s renderer run arbitrary code, usually triggered through a crafted web page—so you should update Chrome if you use it, even though it typically needs an attacker to already have a foothold inside the browser.
CVE-2026-5281 is a use-after-free in Dawn (Chromium) in Google Chrome prior to 146.0.7680.178 that can be triggered by crafted HTML after an attacker already compromises the renderer process, enabling arbitrary code execution within the browser environment (CISA KEV-listed and actively exploited).
What to do now
- Check which Google Chrome version is installed on each business computer (Settings → About Chrome) and identify any systems running versions prior to 146.0.7680.178.
- Update Google Chrome to 146.0.7680.178 or later on all affected machines.
- If you use Red OS or Astra Linux systems, ensure Chrome updates are coming from your trusted update process and complete the upgrade to 146.0.7680.178 or later.
- After updating, review endpoint/browser security alerts for signs of renderer compromise (unusual process behavior, unexpected script/network activity) and escalate any suspicious findings to your IT/security support.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- В браузере Chrome исправили шестую 0-day-уязвимость в этом годуru-ru·Хакер (xakep.ru)·
- Google patches actively exploited Chrome zero-day (CVE-2026-85046)en-us·Help Net Security· Exploited Chrome zero-day
- Google warns of new Chrome zero-day flaw exploited in attacksen-us·BleepingComputer· Exploited Chrome zero-day
- Google Patches 6th Chrome Zero-Day of 2026en-us·SecurityWeek· Exploited Chrome zero-day
- Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Dayen·The Hacker News· Exploited Chrome zero-day
- ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and Moreen·The Hacker News· Exploited Chrome (V8) UNC6240 (ShinyHunters)
- В Chrome исправили уязвимость нулевого дняru-ru·Хакер (xakep.ru)· Exploited Google Chrome (V8 engine) zero-day
- Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Nowen·The Hacker News· Exploited Google Chrome zero-day
- Google patches new Chrome zero-day flaw exploited in the wilden-us·BleepingComputer· Exploited Google Chrome rce
- Google Patches 5th Chrome Zero-Day Exploited in 2026en-us·SecurityWeek· Exploited Google Chrome rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-5281 and every CVE in our database. Create a free account — no credit card required.
Create Free Account