Google Issues Zero-Day Attack Alert For 3.5 Billion Chrome Users

TL;DR AI
2 min readKey summary
Google confirmed CVE-2026-5281, a Chrome zero-day, is being exploited in the wild.
Google released a security update that patches CVE-2026-5281 plus 20 other vulnerabilities.
CISA added the zero-day to its Known Exploited Vulnerabilities catalog and directed some federal agencies to update.
The vulnerability affects the Dawn WebGPU component and is a use-after-free memory issue that can enable code execution.
Windows and Mac users received Chrome version 146.0.7680.177/178 while Linux moved to 146.0.7680.177.


