Google released emergency patches for a critical Chrome vulnerability (CVE-2026-5281) being actively exploited in the wild. The high-severity use-after-free bug in Dawn, Chrome's WebGPU implementation, allows remote attackers who compromised the renderer process to execute arbitrary code via crafted HTML pages. This vulnerability poses significant risks to crypto users as malicious websites could potentially exploit browser-based wallet extensions and steal private keys. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on April 1, 2026, requiring federal agencies to patch by April 15. The exploit comes after Google recently fixed two other high-severity flaws that were also being exploited. Chrome users, especially those using browser-based crypto wallets, should update immediately to version 146.0.7680.178 or later to protect against potential wallet draining attacks.
Chrome Zero-Day CVE-2026-5281 Under Active Exploitation Poses Crypto Wallet Risk
T
The Hacker News
Friday, April 3, 2026·5 min read·Web3
#browser vulnerability#wallet security#Chrome exploit#zero-day
