Google Issues Zero-Day Attack Alert For 3.5 Billion Chrome Users

TL;DR AI
2 min readKey summary
CVE-2026-5281 is a zero-day use-after-free vulnerability in Chrome's Dawn WebGPU component with exploits observed in the wild.
If exploited it can cause data corruption and browser crashes; a Vulners entry says a crafted HTML page could enable arbitrary code execution.
The flaw affects about 3.5 billion Chrome users.
Google issued a high-severity Chrome update and began distributing a fix for this issue along with 20 other vulnerabilities.
Google previously patched three zero-days in Q1 2026 (CVE-2026-2441, CVE-2026-3909, CVE-2026-3910) and eight zero-days across 2025; Chrome team member Srinivas Sista was quoted about access to bug details.


