Vulnerability Management

Actively exploited Chrome zero-day patched

(Credit: MMollaretti – stock.adobe.com)

Updates have been issued by Google to fix 21 vulnerabilities in its Chrome browser, including the actively exploited high-severity zero-day flaw, tracked as CVE-2026-5281, The Hacker News reports.

Threat actors exploiting the use-after-free issue in Dawn, an open-source implementation of the WebGPU standard, could execute arbitrary code via a crafted HTML page, according to the bug's description in the NIST's National Vulnerability Database. Despite acknowledging that an exploit for the vulnerability exists in the wild, Google has not provided additional details regarding the abuse. The update follows fixes for two other high-severity zero-days in recent months, bringing the total number of Chrome zero-days patched this year to four. Users are advised to update to versions 146.0.7680.177/178 for Windows and macOS, and 146.0.7680.177 for Linux.

Users of other Chromium-based browsers, including Microsoft Edge, Brave, Opera, and Vivaldi, should apply fixes as they become available. To ensure protection, navigate to More > Help > About Google Chrome and relaunch.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds