Chrome Patches Critical Zero-Day CVE-2026-5281 Actively Exploited
Emergency Patch for Chrome Zero-Day (CVE-2026-5281) in Dawn Component
- Google released an emergency patch for Chrome to address CVE-2026-5281, a high-severity type confusion vulnerability residing specifically within the browser's Dawn component.
- The flaw allows for active exploitation in the wild, enabling attackers to execute arbitrary code or cause memory corruption in affected Chrome instances.
- This critical vulnerability impacts Google Chrome across Windows, macOS, and Linux platforms, mandating prompt updates to the latest stable version.
Source: SecurityOnline.info | Date: April 01, 2026
CVE-2026-5281 Marks Fourth Actively Exploited Chrome Zero-Day of 2026
- CVE-2026-5281 has been confirmed as the fourth actively exploited zero-day vulnerability discovered in Google Chrome during 2026, highlighting a concerning trend of persistent threats.
- The vulnerability is a type confusion bug in the Dawn component, presenting a significant risk of remote code execution or sandbox escapes.
- Google's rapid response with stable channel updates (e.g., 123.0.6312.86) underscores the severity and active threat landscape for browser users.
Source: Security Affairs | Date: April 01, 2026
Google Attributes Axios npm Supply Chain Attack to North Korean Group UNC1069
- Google's Threat Analysis Group (TAG) attributed the malicious code injection into the popular Axios npm package to UNC1069, a North Korea-linked state-sponsored threat group.
- The attackers specifically targeted repositories belonging to maintainers of the Axios project, aiming to distribute backdoored versions through the supply chain.
- Developers using affected versions of Axios should verify their installations for compromise and update to clean versions to prevent potential client-side web application exploits.
Source: The Hacker News | Date: April 01, 2026
Claude Code Source Leaked via npm Packaging Error, Anthropic Confirms
- Anthropic confirmed that proprietary code for its Claude AI model was inadvertently leaked due to an npm packaging error, exposing sensitive internal project details.
- The accidental publication of an internal package on npm contained the source code, posing a risk of intellectual property theft and potential vulnerability discovery by malicious actors.
- While Anthropic stated no sensitive user data was exposed, the incident highlights supply chain risks even with internal package management.
Source: The Hacker News | Date: April 01, 2026
SentinelOne Autonomous Detection Blocks Trojaned LiteLLM Triggered by Claude Code
- SentinelOne observed and blocked attacks involving a trojanized LiteLLM library, which was triggered by code related to the recently leaked Anthropic Claude AI source code.
- This incident demonstrates the immediate exploitation potential following source code exposure, as attackers quickly weaponized elements of the leaked Claude AI data.
- The detection underscores the importance of advanced endpoint protection capable of identifying and preventing exploits originating from supply chain compromises.
Source: Security Affairs | Date: April 01, 2026
PNG Vulnerabilities Allow Attackers to Trigger Process Crashes, Leak Sensitive Information
- Multiple vulnerabilities have been discovered in the PNG (Portable Network Graphics) image format specification, enabling attackers to cause denial-of-service or information leakage.
- These flaws, if exploited, could lead to crashes in applications processing PNG files, including web browsers and image editors, disrupting user experience.
- Users are advised to keep their operating systems, browsers, and image processing software updated to patched versions that address these newly identified PNG vulnerabilities.
Source: Cyber Security News | Date: April 01, 2026
References
- Chrome Stable Channel Update Fixes 21 Security Flaws, Warns of Actively Exploited Vulnerability - The Cyber Express
- Exploited in the Wild: Google Issues Emergency Patch for Chrome Zero-Day (CVE-2026-5281) in Dawn Component - SecurityOnline.info
- Google fixes fourth actively exploited Chrome zero-day of 2026 - Security Affairs
- Google Attributes Axios npm Supply Chain Attack to North Korean Group UNC1069 - The Hacker News
- Claude Code Source Leaked via npm Packaging Error, Anthropic Confirms - The Hacker News
- SentinelOne autonomous detection blocks trojaned LiteLLM triggered by Claude Code - Security Affairs
- PNG Vulnerabilities Allow Attackers to Trigger Process Crashes, Leak Sensitive Information - Cyber Security News
- CVE-2026-5281 - NVD/MITRE
- New Chrome Zero-Day CVE-2026-5281 Under Active Exploitation — Patch Released - The Hacker News
- Google rolt update uit voor actief aangevallen beveiligingslek in Chrome - Security.nl
- New Chrome Zero-Day Vulnerability Actively Exploited in Attacks — Patch Now - Cyber Security News
- Google fixes Chrome zero-day with in-the-wild exploit (CVE-2026-5281) - Help Net Security
- Google links Axios npm supply chain attack to North Korea-linked APT UNC1069 - Security Affairs