INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Google fixes fourth Chrome zero-day exploited in attacks

| 2026-04-01 20:41 CRITICAL HIGH
Executive Summary AI-generated
Google has fixed a new Chrome zero-day, tracked as CVE-2026-5281. The flaw is a use-after-free bug in Dawn, the WebGPU component used for graphics processing. Google released updates to fix this vulnerability and urges users to update their browser to version 146.0.7680.177/178 (Windows/macOS) or 146.0.7680.177 (Linux). The company is aware that an exploit exists in the wild, but has acknowledged its existence since February 2026.
Technical Mitigations AI-generated
* Use secure coding practices, such as avoiding use-after-free bugs and ensuring memory safety through proper allocation and deallocation of resources. * Regularly update operating systems, browsers, and software to ensure that known vulnerabilities are patched before they can be exploited. * Implement robust security measures, including firewalls, intrusion detection systems, and access controls, to prevent unauthorized access to sensitive data or systems. * Use secure protocols for communication, such as HTTPS, and implement encryption when transmitting sensitive information. * Conduct regular penetration testing and vulnerability assessments to identify potential weaknesses in systems and applications.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-3910CVE-2026-3910 CVE-2026-5281CVE-2026-5281 CVE-2026-3909CVE-2026-3909 CVE-2026-2441CVE-2026-2441
Target & Sectors
Global Scope
Incident Timeline
‎01, 2026
Google released security updates for its Chrome web browser to address 21 vulnerabilities.
organisation Vulnerability / Browser Security
general_metric 21 vulnerabilities
‎February 2026
Google fixes fourth actively exploited Chrome zero-day CVE-2026-5281 in February 2026.
vulnerability CVE-2026-5281
vulnerability CVE-2026-3909
vulnerability CVE-2026-3910
vulnerability CVE-2026-2441
organisation CSS
organisation Skia 2D
general_metric 8.8 CVE-2026 CVSS score
‎March 2026
Threat actors used a fourth actively exploited Chrome zero-day in the V8 JavaScript/WebAssembly engine implementation to target systems.
vulnerability CVE-2026-5281
vulnerability CVE-2026-3909
vulnerability CVE-2026-3910
vulnerability CVE-2026-2441
organisation CSS
organisation Skia 2D
general_metric 8.8 CVE-2026 CVSS score
organisation SecurityAffairs
‎Apr 01, 2026
Google released a patch for its Chrome browser to fix the fourth actively exploited zero-day vulnerability of 2026.
‎2026/04/01
Google fixed a new Chrome zero-day, tracked as CVE-2026-5281.
organisation BleepingComputer
organisation CVE-2026
infrastructure 146.0.7680
organisation Google Chrome
organisation HTML
organisation NIST
organisation National Vulnerability Database
organisation NVD
infrastructure Windows
infrastructure Macos
infrastructure Linux
organisation Stable Desktop
organisation Windows/macOS
organisation Skia 2D
organisation WebAssembly
organisation CSS
organisation Google
organisation Chromium
organisation Microsoft Edge, Brave,
organisation WebGPU
organisation Threat Analysis Group
Tactical Metrics
Metrics
infrastructure
​146.0.7680
Software Version
Metrics
infrastructure
​Windows
Affected Product
Metrics
infrastructure
​Macos
Affected Product
Metrics
infrastructure
​Linux
Affected Product
Intelligence Sources