Google Chrome 149.0.7827.53 — 429 Vulnerabilities Patched (22 Critical); Critical ANGLE/GPU Memory-Safety Sandbox-Escape Chain (CVE-2026-10881 / CVE-2026-10883 / CVE-2026-10898) — Threadlinqs Intelligence
As of 2026-06-08, Google Chrome 149.0.7827.53 — 429 Vulnerabilities Patched (22 Critical); Critical ANGLE/GPU Memory-Safety Sandbox-Escape Chain (CVE-2026-10881 / CVE-2026-10883 / CVE-2026-10898) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 12 indicators of compromise.
Threat ID: TL-2026-0720 · Severity: CRITICAL · CVSS: 9.6 · Status: ACTIVE · Category: VULNERABILITY
Google shipped Chrome stable 149.0.7827.53 (Windows, macOS, Linux, iOS) fixing 429 vulnerabilities, 22 rated critical. The standout criticals are renderer-reachable memory-safety defects in ANGLE and
On 2026-06-04 Google promoted Chrome 149.0.7827.53 to the stable channel across Windows, macOS, Linux and Chrome for iOS, resolving 429 distinct security defects, 22 of which carry Chromium 'Critical' severity. The release is dominated by memory-safety bugs in the graphics and GPU paths, all reachable from untrusted web content rendered in a tab.
CVE-2026-10881 is an out-of-bounds read and write in ANGLE (Almost Native Graphics Layer Engine), Chrome's OpenGL ES translation layer that backs WebGL and WebGPU. A crafted HTML page driving malformed graphics state triggers OOB access within the GPU process, which ANGLE runs inside. NVD scores it CVSS 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H) with a CHANGED scope, reflecting that successful exploitation crosses the renderer/GPU sandbox boundary toward a sandbox escape (CWE-125, CWE-787).
CVE-2026-10883 is a type confusion in ANGLE leading to heap corruption (CVSS 8.8, CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Conflating one object type for another inside the GPU process gives an attacker controlled read/write primitives over the heap — a classic stepping stone toward arbitrary code execution in the GPU process.
CVE-2026-10898 is a stack buffer overflow in the GPU component (CVSS 8.3, CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H, CWE-121). NVD's description is explicit that it requires an attacker who has 'already compromised the renderer process' and then performs a sandbox escape via a crafted HTML page — i.e. it is the back half of a two-stage chain in which a renderer bug (such as a V8 or DOM use-after-free) is paired with a GPU-process memory-safety bug to break out of the sandbox.
Beyond the three headline ANGLE/GPU criticals, the patch set closes a broad sweep of use-after-free conditions across Network, Chromecast, Cast Streaming, Chromoting (Chrome Remote Desktop), Printing, FileSystem, GFX and Ozone, plus the iOS WebKit-adjacent layer; high-severity type confusion and implementation bugs in V8; use-after-free in WebRTC, WebAuthentication, Audio and UI; and integer overflows in Dawn (WebGPU backend), DevTools, and Media. Google is withholding detailed bug-tracker entries and restricting access to the bug details until a majority of users have updated, per its standard disclosure embargo.
At time of analysis there is no confirmed in-the-wild exploitation and no public proof-of-concept for the three tracked CVEs. However, ANGLE and GPU-process memory-safety bugs are a historically favored target for browser exploit chains because the GPU process is less hardened than the renderer and sits adjacent to the OS graphics stack. The combination of network attack vector, no privileges required, and only user interaction (visiting a page) makes these prime candidates for weaponization once details or patches are diffed.
Weaknesses (CWE)
CWE-125, CWE-787, CWE-843, CWE-121, CWE-416, CWE-190
Target sectors: all sectors, government, financial, healthcare, technology, education
Target regions: Global
Detections & IOCs
As of 2026-08-07, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 12 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-10881, CVE-2026-10883, CVE-2026-10898, T1189, T1203, T1204.001, T1068, T1611, T1211, T1055, T1587.004, T1608.004, T1592.002