What is CVE-2026-5281?
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Timeline
- 2026-04-01Published to the U.S. National Vulnerability Database (NVD)
- 2026-04-01Added to the CISA Known Exploited Vulnerabilities (KEV) catalog
- 2026-04-02First covered in a defend.network daily briefing
- 2026-04-15CISA federal remediation deadline (BOD 22-01)
- 2026-07-24NVD record last updated
CISA Known Exploited Vulnerability
Google Dawn Use-After-Free Vulnerability
Affected product
Google Dawn
NVD also lists CPE entries for: Google Chrome, Apple Macos, Linux Kernel, Microsoft Windows
References
- https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_31.html
- https://issues.chromium.org/issues/491518608
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-5281
- https://nvd.nist.gov/vuln/detail/CVE-2026-5281
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Referenced in our briefings & reports
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.