Google Dawn Use-After-Free Vulnerability

Release Date: 1st April 2026

Impact : HIGH / CRITICAL

TLP Rating: Clear

Communication and Digital Transformation (DCDT through CERT Vanuatu (CERTVU), provides the following advisory

This alert is relevant to Organizations and System/Network administrators that utilize the above products. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-5281 is a high-severity use-after-free vulnerability (CVSS 8.8) affecting the Google Chrome browser. The flaw exists in Dawn, the implementation of the WebGPU (graphics) API used by Chromium-based browsers.

 

References

  1. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  2. https://www.cve.org/CVERecord?id=CVE-2026-5281