⚡️ 0-Day Alert: Google Chrome GPU Remote to Elevation of Privilege exploit in the wild
Update Chrome to 146.0.7680.177/178
CVE-2026-5281: Dawn Server Use-after-free due to improper clearing of callbacks upon object destruction
🔒 Issue: https://issues.chromium.org/issues/491518608
The bug is interesting: a partial EoP that can potentially be triggered remotely via WebGPU API calls. Normally this chain of impact requires at least 2-3 separate bugs. The fact that it was cherry-picked to M146 confirms high-to-critical impact.
Patched in 146.0.7680.177/178 for Windows/Mac and 146.0.7680.177 for Linux on 31st March