Skip to content
COOEY

EXPOSURES › CVE-2026-5281

CVE-2026-5281

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-04-01 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-5281 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 45/100 rceexploited-in-wildransomwaresupply-chain

Google Dawn (Chrome/Edge/Opera) use-after-free vulnerability enables remote code execution via crafted HTML.

A remote use-after-free flaw in Google Dawn allows attackers to execute arbitrary code through a malicious webpage, impacting all Chromium-based browsers. DIB orgs must patch immediately to prevent ransomware or espionage via compromised browser processes.

Shame score — A critical RCE vulnerability in a widely deployed browser product that is actively exploited, though not zero-day.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized