LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-5281: Google Dawn Use-After-Free Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 1, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 15, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-5281 to its Known Exploited Vulnerabilities catalog on Apr 1, 2026, with a federal patch deadline of Apr 15, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability…

A use-after-free vulnerability exists in Google Dawn, the graphics and WebGPU implementation used by multiple Chromium-based browsers. A remote attacker who has already compromised the renderer process can leverage a crafted HTML page to execute arbitrary code. The issue matters because Dawn ships in widely deployed browsers, and successful exploitation can lead to further compromise of the browser process and, potentially, the underlying system.

How it works

The weakness is classified as CWE-416, a use-after-free condition. In this class of flaw, memory is freed while a pointer to it remains in use. An attacker who controls the renderer process can arrange for subsequent operations on that dangling pointer, resulting in arbitrary code execution within the renderer context.

Exploitation begins with a crafted HTML page delivered to the browser. No further mechanics are documented in the available summary; confirm the precise trigger conditions against the vendor advisory.

Am I affected? How to find it in your systems

Google Dawn is present in Chromium-based browsers and any application that embeds the Chromium renderer or WebGPU stack. Inventory all instances of Google Chrome, Microsoft Edge, Opera, and other Chromium-derived products across endpoints and servers.

Exact affected versions and configurations must be confirmed against the vendor advisory.

How to remediate

Apply the vendor-supplied update referenced in the official advisory. This is the primary remediation for the use-after-free condition.

If you can't patch immediately

Until the update can be applied, reduce exposure through the following controls:

Follow applicable CISA BOD 22-01 guidance for cloud-hosted instances and discontinue use of the product if mitigations cannot be implemented.

If your data may have been exposed

Actively exploited vulnerabilities of this type have led to unauthorized access and data breaches in other incidents. Organizations can run a free exposure scan of their domains and associated email addresses against known breach data to determine whether credentials or other information have already appeared in public repositories.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedGoogle · Dawn
WeaknessCWE-416
Added to CISA KEVApr 1, 2026
Federal patch deadlineApr 15, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities