New Chrome Zero-Day CVE-2026-5281 Under Active Exploitation — Patch Released
嗯,用户让我总结这篇文章的内容,控制在一百个字以内,而且不需要用“文章内容总结”之类的开头。首先,我需要仔细阅读文章,抓住主要信息。 文章讲的是谷歌发布了Chrome的安全更新,修复了21个漏洞,其中包括一个零日漏洞CVE-2026-5281。这个漏洞已经被野外利用了。漏洞涉及到Dawn组件中的use-after-free错误,影响到旧版本的Chrome。谷歌没有透露更多细节,但承认漏洞存在。用户需要更新到特定版本以确保安全。 接下来,我需要把这些信息浓缩到100字以内。要包括谷歌发布更新、修复21个漏洞、零日漏洞被利用、影响范围以及建议用户更新。 可能的结构是:谷歌发布Chrome安全更新,修复21个漏洞,包括已被利用的零日漏洞CVE-2026-5281,涉及Dawn组件的use-after-free错误。建议用户更新至最新版本以防范风险。 检查一下字数是否在限制内,并确保信息准确无误。 </think> 谷歌发布Chrome安全更新修复21个漏洞,其中包括已被利用的零日漏洞CVE-2026-5281,涉及Dawn组件中的use-after-free错误。建议用户更新至最新版本以防范风险。 2026-4-1 11:42:0 Author: thehackernews.com(查看原文) 阅读量:3 收藏

Vulnerability / Browser Security

Google on Thursday released security updates for its Chrome web browser to address 21 vulnerabilities, including a zero-day flaw that it said has been exploited in the wild.

The high-severity vulnerability, CVE-2026-5281 (CVSS score: N/A), concerns a use-after-free bug in Dawn, an open-source and cross-platform implementation of the WebGPU standard.

"Use-after-free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page," according to a description of the flaw in the NIST's National Vulnerability Database (NVD).

As is customary for these alerts, Google did not provide any further details on how the shortcoming is being exploited and who may be behind the effort. This is typically done so as to ensure that a majority of users are updated with a fix and prevent other actors from joining the exploitation bandwagon.

"Google is aware that an exploit for CVE-2026-5281 exists in the wild," the company acknowledged.

The development arrives merely after Google shipped fixes for two high-severity flaws (CVE-2026-3909 and CVE-2026-3910) that were exploited as zero-days. In February, the tech giant also addressed an actively exploited use-after-free bug in Chrome's CSS component (CVE-2026-2441). In total, Google has patched a total of four actively weaponized Chrome zero-days since the start of the year.

For optimal protection, users are advised to update their Chrome browser to versions 146.0.7680.177/178 for Windows and Apple macOS, and 146.0.7680.177 for Linux. To make sure the latest updates are installed, users can navigate to More > Help > About Google Chrome and select Relaunch.

Users of other Chromium-based browsers, such as Microsoft Edge, Brave, Opera, and Vivaldi, are also advised to apply the fixes as and when they become available.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2026/04/new-chrome-zero-day-cve-2026-5281-under.html
如有侵权请联系:admin#unsafe.sh