CVE-2026-10881
CVSS 9.6 CRITICAL: out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. Microsoft patch: Release Notes.
Vulnerabilities & Exploits
The bottleneck is shifting from finding bugs to absorbing them. Cheap AI runs can now hand defenders a stack of reproducible flaws faster than teams can verify impact, sort priority, and ship fixes, and that pressure hits hardest in widely embedded code that sits inside other products.
This week brought both sides of that shift. A security startup said an autonomous agent found 21 confirmed FFmpeg zero-days with reproducible proofs of concept for about $1,000 a run, while Google shipped Chrome 149 with 429 security fixes, the most ever in one release, after overhauling its bounty program to handle a flood of AI-generated reports. The point is not the exact count; it is the growing gap between vulnerability throughput and human response capacity.
2 sources · Jun 12
CVSS 9.6 CRITICAL: out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. Microsoft patch: Release Notes.
SecurityWeek
Chrome 149 Update Patches 28 Vulnerabilities
The browser refresh resolved critical and high-severity security defects, including a dozen use-after-free bugs.
originalThe Hacker News
AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs
AI found 21 FFmpeg zero-days, some 20 years old; Chrome 149 patched 429 bugs, including 100+ critical/high flaws.
originalSecurityWeek
Chrome 149 Patches 429 Vulnerabilities
Over 100 bugs are critical or high-severity, mainly use-after-free and insufficient validation of untrusted input flaws.
originalPart of the PlainSec briefing for 2026-06-06
Every edition of this story: AI Bug Hunts Are Swamping Human Triage