Chrome’s Fourth Zero-Day of 2026 Proves WebGPU Is the Browser’s New Attack Surface
On March 31, 2026, Google shipped an emergency patch for CVE-2026-5281, an already-exploited use-after-free in Dawn, Chromium’s WebGPU implementation. It’s Chrome’s fourth zero-day in four months — and a clear signal that low-level graphics APIs have become the browser exploitation frontier.