CVE-2026-10881
CVSS 9.6 CRITICAL: out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. Patch Microsoft: Release Notes.
Vulnerabilità · 109 giorni fa
Il collo di bottiglia si sta spostando dalla scoperta dei bug all’assorbirli. Le esecuzioni economiche con AI possono ora consegnare ai difensori una pila di vulnerabilità riproducibili più velocemente di quanto i team possano verificarne l’impatto, ordinarne la priorità e distribuire le correzioni, e quella pressione colpisce più duramente il codice ampiamente incorporato che si trova all’interno di altri prodotti.
CVSS 9.6 CRITICAL: out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. Patch Microsoft: Release Notes.
2 fonti che coprono questa storia
Chrome 149 Update Patches 28 Vulnerabilities
The browser refresh resolved critical and high-severity security defects, including a dozen use-after-free bugs.
AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs
AI found 21 FFmpeg zero-days, some 20 years old; Chrome 149 patched 429 bugs, including 100+ critical/high flaws.
Chrome 149 Patches 429 Vulnerabilities
Over 100 bugs are critical or high-severity, mainly use-after-free and insufficient validation of untrusted input flaws.
Part of the PlainSec briefing for 2026-06-07