Google Patches Actively Exploited Chrome Flaw, Warns of Full Device Compromise
Google has released an urgent security update to address multiple high-severity vulnerabilities in Chrome, including one that is already being actively exploited in the wild.
The vulnerability, tracked as CVE-2026-5281, is a use-after-free flaw affecting Chrome's WebGPU implementation through its Dawn GPU abstraction layer.
Attackers can exploit this flaw by triggering memory mismanagement within the GPU processing pipeline, leading to memory corruption and potentially allowing them to execute arbitrary code within the browser context.
The patch release addressed 21 vulnerabilities, many involving memory-safety issues such as use-after-free and heap buffer overflows across components, including WebGL, WebCodecs, CSS, and the V8 JavaScript engine.