CVE-2026-5281
HIGHCISA KEVEPSS 91th pctlDescription
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. Google is aware that an exploit for CVE-2026-5281 exists in the wild.
How to fix
TridentStack Control can deploy fixes like this automatically across your Windows, macOS, and Linux fleet. See how it works
Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.
CVSS v3 Vector
Exploitability
Impact
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploit Intelligence
High risk: more likely to be exploited than 91% of all known CVEs.
Google Dawn Use-After-Free Vulnerability
Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: 2026-04-15
References
Related Vulnerabilities
Other CWE-416 (Use After Free) vulnerabilities, ordered by exploit likelihood. View all
| CVE | Severity | CVSS | EPSS | Exploited | Fix |
|---|---|---|---|---|---|
| CVE-2019-0708 | Critical | 9.8 | 100% | KEV + Ransom | - |
| CVE-2021-31166 | Critical | 9.8 | 100% | KEV | Fix |
| CVE-2015-5119 | Critical | 9.8 | 99% | KEV | - |
| CVE-2010-3962 | High | 8.1 | 97% | KEV | - |
| CVE-2015-0313 | Critical | 9.8 | 96% | KEV | Fix |
| CVE-2017-9798 | High | 7.5 | 95% | - | Fix |
Embed a live status badge for CVE-2026-5281
Markdown
[](https://tridentstack.com/cve/CVE-2026-5281)HTML
<a href="https://tridentstack.com/cve/CVE-2026-5281"><img src="https://tridentstack.com/cve/badge/CVE-2026-5281.svg" alt="CVE-2026-5281"></a>Find and fix vulnerabilities across your fleet
TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.
This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2026-04-02.