← Back to browse · API

CVE-2026-5281

Severity
HIGH
CVSS
8.8
EPSS
0.05036
Risk score
58.76
CISA KEV
Yes
PoC
No
Published
2026-04-01
Modified
2026-04-02
First seen
2026-08-05
Aliases
CNVD-2026-24165, EUVD-2026-17795, GHSA-XF76-839H-PFPM
Products
Google Chrome <146.0.7680.178, Google:Chrome 146.0.7680.178 <146.0.7680.178, Google:Dawn, apple:macos, google:chrome, linux:linux_kernel, microsoft:windows
Sources
cnvd CNVD-2026-24165
nvd CVE-2026-5281
cisa.gov CVE-2026-5281
euvd EUVD-2026-17795

Description

Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

References