Global NewsHigh Priority (9/10)

Google Chrome 146 Patches Actively Exploited Zero-Day Vulnerability

Google has released Chrome 146 fixing 21 vulnerabilities, including a zero-day (CVE-2026-5281) actively exploited in the wild—a use-after-free flaw in the Dawn graphics layer.

Key Points

  • Chrome 146 patches 21 vulnerabilities including one actively exploited zero-day
  • CVE-2026-5281 is a use-after-free vulnerability in Chrome's Dawn graphics layer
  • All vulnerabilities were reported in March 2026
  • Google has not disclosed details about the attacks exploiting the zero-day

Full Details

Google has announced the release of Chrome 146, a security update addressing 21 vulnerabilities in the popular web browser. Among these patches is a zero-day vulnerability tracked as CVE-2026-5281, which has been actively exploited in the wild. The vulnerability is described as a use-after-free issue存在于Chrome's Dawn graphics layer, which handles graphics rendering. Google has not disclosed details about the attacks exploiting this vulnerability or the specific threat actors involved. All 21 vulnerabilities patched in this update were reported in March 2026, and the company has not yet determined the bug bounty payments for the researchers who reported these issues. Users are strongly advised to update their Chrome browsers immediately to protect against potential exploits.

Why It Matters

Active zero-day exploits in widely-used browsers like Chrome pose significant risks to millions of users worldwide. This highlights the ongoing cat-and-mouse game between browser vendors and threat actors, emphasizing the critical importance of timely software updates.

Sourcesecurityweek.com

Get stories like this delivered daily

AI-curated news, personalized to your interests. Zero noise.

Start 7-Day Free Trial →

More in Global News