PT-2026-29459 · Google+1 · Google Chrome+1

86Ac1F1587B71893Ed2Ad792Cd7Dde32

·

Published

2026-03-31

·

Updated

2026-05-24

·

CVE-2026-5281

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 146.0.7680.178 Chromium-based browsers (Edge, Brave, Opera, Vivaldi) (affected versions not specified) iOS versions prior to 26
Description A use-after-free issue exists in Dawn, the WebGPU (Web Graphics Library Next) layer in Chromium. This flaw allows a remote attacker to execute arbitrary code within the renderer process via a specially crafted HTML page. Successful exploitation typically requires a prior compromise of the renderer process and user interaction. This issue has been actively exploited in the wild and is associated with the DarkSword exploit chain on iOS to achieve remote code execution, sandbox escape, and privilege escalation.
Recommendations Update to version 146.0.7680.178 or later. Apply vendor-specific security updates. Update to iOS 26 or apply the iOS 18 backported security updates. As a temporary workaround, consider disabling WebGPU or hardware acceleration and restricting access to untrusted web content.

Exploit

Fix

LPE

RCE

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2026-04540
CVE-2026-5281
OPENSUSE-SU-2026:10487-1
OPENSUSE-SU-2026:20460-1

Affected Products

Google Chrome
Red Os