ctipilot.ch
← Back to Daily brief 2026-06-07
HIGHCVE-2026-10881vulnerability

CVE-2026-10881 — Google Chrome (ANGLE graphics engine): out-of-bounds read/write enabling sandbox escape (CVSS 9.6)

discovered 2026-06-07 05:00 UTCrun 2026-06-07-0885f1232 sourcesmulti-source

Google shipped Chrome 149 (stable 149.0.7827.53/54) on 2026-06-02, patching 429 vulnerabilities — the largest single-release count in Chrome's history, with over 100 rated critical or high (Google Chrome Releases, 2026-06-02; SecurityWeek, 2026-06-05). The highest-severity externally-reported fix is CVE-2026-10881 (CVSS 9.6), an out-of-bounds read and write in ANGLE — Chrome's graphics-translation layer that maps WebGL/GPU calls to the host graphics API — which SecurityWeek reports remote attackers could exploit to escape Chrome's sandbox via a crafted HTML page, with no interaction beyond visiting the page. The sandbox-escape class is the consequential one for enterprises: a renderer compromise chained through ANGLE yields code execution in the browser process, the launch point for subsequent host privilege-escalation chains. No in-the-wild exploitation has been reported. Chrome auto-updates, but managed and extended-stable fleets routinely lag; verify deployment has reached 149.0.7827.53+ via asset inventory or the ADMX update policy, and confirm no MDM version-pin is holding endpoints back. Maps to T1203 (Exploitation for Client Execution).

CVE Summary Table

The table consolidates the CVE-bearing items across this brief; only CVE-2026-10881 is a § 2 trending-vulnerability entry — the Keycloak and FFmpeg rows are cross-references to § 5 and § 3 respectively.

CVE Product CVSS EPSS KEV Exploited Patch Source
CVE-2026-10881 Google Chrome ANGLE graphics engine 9.6 ~0.04 No No Chrome 149.0.7827.53+ SecurityWeek
CVE-2026-9704 Keycloak < 26.6.3 (token exchange) n/a n/a No No Keycloak 26.6.3 Keycloak
CVE-2026-4874 Keycloak < 26.6.3 (OIDC token endpoint) n/a n/a No No Keycloak 26.6.3 Keycloak
CVE-2026-39210 FFmpeg (TS demuxer; +8 numbered) n/a n/a No No (PoC public) Upstream fix commits depthfirst

Remote attackers could exploit the vulnerability to escape Chrome's sandbox via crafted HTML pages

Chrome 149 was released with patches for 429 vulnerabilities, including over 100 critical and high-severity bugs.

SecurityWeek

Defender actions

  • Confirm managed Chrome fleets have reached 149.0.7827.53+ (§ 2) — check asset inventory / ADMX policy and ensure no MDM version-pin is holding endpoints on a vulnerable build of the ANGLE sandbox-escape CVE-2026-10881.

ATT&CK mapping

1 technique mapped from the cited reporting · MITRE ATT&CK v19.2

Execution TA0002
T1203Exploitation for Client Execution

Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution on a remote system because they can be used to gain access to that system. Users will expect to see files related to the applications they commonly used to do work, so they are a useful target for exploit research and development because of their high utility.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.