Active Dawn Zero-Day in Chrome Enables Sandbox Escape
Every Chrome user who loads a crafted page risks remote code execution due to a use-after-free flaw in the Dawn WebGPU component. This zero-day is the fourth actively exploited Chrome vulnerability in 2026, showing attackers are repeatedly targeting Chromium's graphics rendering subsystems. Standard patching is urgent because the flaw allows arbitrary code execution when the renderer process is compromised.
The vulnerability, tracked as CVE-2026-5281, affects Chrome versions before 146.0.7680.177/178 and corresponding Chromium builds. Google confirmed an exploit exists in the wild and released fixes in Chrome 146.0.7680.178 for macOS and 146.0.7680.177 for Windows and Linux. This follows multiple recent fixes in Dawn, WebGL, and other graphics components, highlighting a focused attack trend on browser graphics stacks.
This pattern of repeated zero-days in Chromium's rendering components suggests attackers are intensifying efforts to exploit complex graphics subsystems. The risk persists as these components expand the browser's attack surface beyond traditional web content, requiring ongoing vigilance beyond routine patching.