CVE-2026-10881
CVSS 9.6 CRITICAL: out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. Patch Microsoft: Release Notes.
Vulnerabilità ed exploit
Il collo di bottiglia si sta spostando dalla scoperta dei bug all’assorbirli. Le esecuzioni economiche con AI possono ora consegnare ai difensori una pila di vulnerabilità riproducibili più velocemente di quanto i team possano verificarne l’impatto, ordinarne la priorità e distribuire le correzioni, e quella pressione colpisce più duramente il codice ampiamente incorporato che si trova all’interno di altri prodotti.
2 fonti · 12 giu
CVSS 9.6 CRITICAL: out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. Patch Microsoft: Release Notes.
SecurityWeek
Chrome 149 Update Patches 28 Vulnerabilities
The browser refresh resolved critical and high-severity security defects, including a dozen use-after-free bugs.
originaleThe Hacker News
AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs
AI found 21 FFmpeg zero-days, some 20 years old; Chrome 149 patched 429 bugs, including 100+ critical/high flaws.
originaleSecurityWeek
Chrome 149 Patches 429 Vulnerabilities
Over 100 bugs are critical or high-severity, mainly use-after-free and insufficient validation of untrusted input flaws.
originalePart of the PlainSec briefing for 2026-06-07
Every edition of this story: Le cacce ai bug con AI stanno sommergendo il triage umano