ctipilot.ch

Google Chrome ANGLE graphics engine out-of-bounds read/write → sandbox escape (CVSS 9.6); Chrome 149 record 429-patch release

cve · CVE-2026-10881

Coverage timeline
1
first 2026-06-07 → last 2026-06-07
Peak priority
high
1 high
Sources cited
4
4 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
1
pinned v19.1 · see below

ATT&CK techniques

1 technique observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Execution TA0002

T1203Exploitation for Client Execution×1

Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution on a remote system because they can be used to gain access to that system. Users will expect to see files related to the applications they commonly used to do work, so they are a useful target for exploit research and development because of their high utility.

Evidence: 2026-06-07/cve-2026-10881-google-chrome-angle-graphics-engine-out-of-bo · ATT&CK page ↗

Story timeline

  1. 2026-06-07CVE-2026-10881 — Google Chrome (ANGLE graphics engine): out-of-bounds read/write enabling sandbox escape (CVSS 9.6)
    trending-vulnerabilities

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • chromereleases.googleblog.com1 (25%)
  • depthfirst.com1 (25%)
  • keycloak.org1 (25%)
  • securityweek.com1 (25%)

explore in graph

Entries about Google Chrome ANGLE graphics engine out-of-bounds read/write → sandbox escape (CVSS 9.6); Chrome 149 record 429-patch release (1)

2026-06-07 · view entry permalink →

CVE-2026-10881 — Google Chrome (ANGLE graphics engine): out-of-bounds read/write enabling sandbox escape (CVSS 9.6)

Google shipped Chrome 149 (stable 149.0.7827.53/54) on 2026-06-02, patching 429 vulnerabilities — the largest single-release count in Chrome's history, with over 100 rated critical or high (Google Chrome Releases, 2026-06-02; SecurityWeek, 2026-06-05). The highest-severity externally-reported fix is CVE-2026-10881 (CVSS 9.6), an out-of-bounds read and write in ANGLE — Chrome's graphics-translation layer that maps WebGL/GPU calls to the host graphics API — which SecurityWeek reports remote attackers could exploit to escape Chrome's sandbox via a crafted HTML page, with no interaction beyond visiting the page. The sandbox-escape class is the consequential one for enterprises: a renderer compromise chained through ANGLE yields code execution in the browser process, the launch point for subsequent host privilege-escalation chains. No in-the-wild exploitation has been reported. Chrome auto-updates, but managed and extended-stable fleets routinely lag; verify deployment has reached 149.0.7827.53+ via asset inventory or the ADMX update policy, and confirm no MDM version-pin is holding endpoints back. Maps to T1203 (Exploitation for Client Execution).

CVE Summary Table

The table consolidates the CVE-bearing items across this brief; only CVE-2026-10881 is a § 2 trending-vulnerability entry — the Keycloak and FFmpeg rows are cross-references to § 5 and § 3 respectively.

CVE Product CVSS EPSS KEV Exploited Patch Source
CVE-2026-10881 Google Chrome ANGLE graphics engine 9.6 ~0.04 No No Chrome 149.0.7827.53+ SecurityWeek
CVE-2026-9704 Keycloak < 26.6.3 (token exchange) n/a n/a No No Keycloak 26.6.3 Keycloak
CVE-2026-4874 Keycloak < 26.6.3 (OIDC token endpoint) n/a n/a No No Keycloak 26.6.3 Keycloak
CVE-2026-39210 FFmpeg (TS demuxer; +8 numbered) n/a n/a No No (PoC public) Upstream fix commits depthfirst

Remote attackers could exploit the vulnerability to escape Chrome's sandbox via crafted HTML pages

Chrome 149 was released with patches for 429 vulnerabilities, including over 100 critical and high-severity bugs.

SecurityWeek
vulnerability07 Jun 05:00Zmulti-sourceOpen finding ↗