Threat reportThreat IntelligenceTL-2026-1795

Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072 Chrome Security Bugs Across Chrome 149/150, Including 13-Year-Old ANGLE Sandbox-Escape (CVE-2026-10881)

ACTIVE

Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072 (TL-2026-1795), also tracked as Chrome AI Security Overhaul, is a info-severity tracked intrusion set, first published 2026-07-31. It has no confirmed attribution, affects Google Google Chrome, references 2 CVEs (CVE-2026-10881, CVE-2026-10882), maps to 17 MITRE ATT&CK techniques (T1005, T1041, T1059), and is covered by 9 detection rules and 24 indicators of compromise.

Severity
INFOAssessed severity
CVEs
2Referenced vulnerabilities
Techniques
17MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
24Indicators of compromise

Key facts for TL-2026-1795

Threat ID
TL-2026-1795
Also known as
Chrome AI Security Overhaul, Chrome 1,072-bug AI patching wave
Severity
INFO
Status
ACTIVE
Category
THREAT_INTEL
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, government administration, financial-services, health, critical-infrastructure, education, retail
Target regions
Global
Detection rules
9
Indicators of compromise
24

Malware and tooling in Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072

Malware and tooling: Big Sleep, Claude Mythos, CodeMender, GOSSIP, Gemini Deep Think, MiraclePtr, Naptime, OSS-Fuzz

How Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072 works

Google's Chrome Security Team, working with Google DeepMind and Project Zero, reports that a Gemini-powered agent framework combined with the Big Sleep vulnerability-discovery agent and the CodeMender code-security agent drove Chrome 149 and Chrome 150 to fix 1,072 security bugs combined — more than the prior 23 stable releases combined — including a 13-year-old ANGLE sandbox-escape bug (crbug.com/487383169) that could let a compromised renderer read local files, and blocked over 20 vulnerabilities from reaching production in May 2026 alone, including one critical S1+ issue.

This is a defensive-tooling/threat-intel research signal, not an exploited threat: Google has no report of active exploitation, threat-actor involvement, or a single CVSS-scored vulnerability driving this record. Instead it documents a structural shift in how Chrome's security bugs are found, triaged, and patched, disclosed by Google's Chrome Security Team in the July 30, 2026 post 'Stronger with every update: How we're making Chrome and the web safer in the AI Era' (blog.google/security/chrome-stronger-with-every-update/).

Google built a custom agent harness on Gemini (and other models) with a knowledge base covering Chrome's full Git history, all previously identified CVEs, and per-component SECURITY.md trust-boundary documentation. The harness runs a four-phase triage pipeline: (1) filtering spam/duplicate reports, (2) reproducing the bug with stack traces on affected OS/browser versions, (3) enriching metadata (bug-introduction timeline, severity rating), and (4) automatically routing the bug to the correct human component owner. A separate multi-agent fixing workflow uses a 'fixing agent' to generate candidate patches, a 'critic agent' to evaluate them, and 'test-writing agents' to produce platform-agnostic regression tests before human engineer review — humans remain the final approver; no patch is auto-committed.

Two DeepMind/Project Zero tools are integrated directly into Chrome's continuous-integration pipeline, running every 24 hours across all code changes: Big Sleep (an AI vulnerability-discovery agent, successor lineage to the earlier Project Zero 'Naptime' framework, that has found bugs in the V8 JavaScript engine and Chrome's graphics stack) and CodeMender (a DeepMind AI agent, launched in preview around October 2025, that uses Gemini Deep Think reasoning plus static analysis, dynamic analysis, differential testing, fuzzing, and SMT solvers to find root causes and generate validated patches — it has upstreamed 72 security fixes to open-source projects, including complex object-lifetime fixes and `-fbounds-safety` annotations added to the libwebp image library, across codebases as large as 4.5 million lines). As of May 2026, Google is folding CodeMender into its Gemini Enterprise Agent Platform for broader enterprise AppSec use (with identity/gateway/observability integration); analysts such as Chris Steffen (VP, Enterprise Management Associates) have flagged that enterprises will want governance controls and visibility into false-positive/regression rates before trusting autonomous remediation as a point solution.

The headline discovery cited by Google is a sandbox-escape vulnerability (tracked at crbug.com/487383169 / issues.chromium.org/issues/487383169) that had persisted in Chrome's codebase for more than 13 years, which would let a compromised renderer process trick the browser into reading local files outside its sandbox boundary. Separately, and independently confirmed via NVD, Chrome 149 (149.0.7827.53/54 for Windows/macOS, 149.0.7827.53 for Linux; released 2026-06-04) fixed 429 security bugs — 22 of them Critical, reported as CVE-2026-10881 through CVE-2026-10902 — including CVE-2026-10881 (out-of-bounds read/write in ANGLE, CVSS 3.1 9.6 Critical, CWE-125/CWE-787, sandbox escape via a crafted HTML page) and CVE-2026-10882 (use-after-free in Network, CVSS 3.1 8.8 High, CWE-416, remote code execution via a crafted HTML page). Chrome 150 (150.0.7871.46/47 Windows/macOS, 150.0.7871.46 Linux; released 2026-06-30) fixed 382 security bugs, 15 of them Critical (reported as CVE-2026-13774 through CVE-2026-13788), predominantly use-after-free flaws across Extensions, GPU, Browser, Bluetooth, WebUSB, Views, Chromoting, and Ozone components. Neither the Chrome 149 nor Chrome 150 critical CVEs appear in the CISA Known Exploited Vulnerabilities catalog as of this record — press reporting states none of the patched Chrome 150 issues were known to be actively exploited in the wild.

Google also reports that in May 2026 the AI pipeline blocked more than 20 vulnerabilities from ever reaching a production release, including one critical S1+-severity issue, and that Chrome Vulnerability Reward Program report volume for March 2026 alone exceeded the program's entire 2025 annual total (16, then 21, then 100 vulnerabilities attributed to internal Google discovery across successive April/May 2026 releases, per SecurityWeek's tracking). The trend is cross-vendor: SecurityWeek reports Mozilla found 270+ Firefox vulnerabilities using Anthropic's 'Claude Mythos' model (available to roughly 50 organizations including Google), and that Microsoft and Palo Alto Networks are finding vulnerabilities with their own internal AI tooling. Google frames the resulting spike in disclosed bug counts as improved detection, not a decline in Chrome's underlying security, and is simultaneously piloting faster patch delivery — two security releases per week and 'dynamic patching' to hot-swap background browser processes without a full restart — to shrink the patch gap that a faster AI-driven discovery rate would otherwise widen. Longer-running Chrome memory-safety investments referenced alongside this effort include MiraclePtr/MiracleObject (use-after-free mitigation), the Spanification project (97% of first-party Chrome code compiles cleanly under strict unsafe-buffer/std::span warnings), checked-math integer-overflow protection, ongoing Rust migration of memory-unsafe components, and GOSSIP (Google's Open Source Security Intelligence Platform) for supply-chain risk scoring across Chrome's 2,300+ third-party dependencies (~1,700 shipped to users).

No IOCs, threat-actor attribution, or exploitation-in-the-wild are asserted anywhere in the sourced reporting; this record exists to give defenders visibility into Google's AI-augmented vulnerability-management pipeline, the specific CVEs it has already produced and patched, and the broader industry trend of LLM-driven vulnerability discovery/remediation that is materially increasing disclosed bug volume across major browser vendors.

MITRE ATT&CK techniques used in TL-2026-1795

Collection

T1005 Data from Local System

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution; T1204 User Execution

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Command and Control

T1071 Application Layer Protocol

Persistence

T1176 Software Extensions

Initial Access

T1189 Drive-by Compromise

Defense Evasion

T1211 Exploitation for Stealth

Discovery

T1518 Software Discovery

Credential Access

T1539 Steal Web Session Cookie; T1552 Unsecured Credentials

Resource Development

T1587 Develop Capabilities; T1588 Obtain Capabilities

reconnaissance

T1592 Gather Victim Host Information

Reconnaissance

T1596 Search Open Technical Databases

Affected products and versions in Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072

  • Google — Google Chrome
    Vulnerable versions: prior to 149.0.7827.53 (Linux); prior to 149.0.7827.53/54 (Windows/macOS)
    Fixed in: 149.0.7827.53 (Linux); 149.0.7827.53/54 (Windows/macOS)
  • Google — Google Chrome
    Vulnerable versions: prior to 150.0.7871.46 (Linux); prior to 150.0.7871.46/47 (Windows/macOS)
    Fixed in: 150.0.7871.46 (Linux); 150.0.7871.46/47 (Windows/macOS)

Remediation for Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072

Patches

  • Chrome 149 (149.0.7827.53/54 Windows/macOS, 149.0.7827.53 Linux, released 2026-06-04) — 429 security fixes including 22 Critical CVEs reported as CVE-2026-10881 through CVE-2026-10902
  • Chrome 150 (150.0.7871.46/47 Windows/macOS, 150.0.7871.46 Linux, released 2026-06-30) — 382 security fixes including 15 Critical CVEs reported as CVE-2026-13774 through CVE-2026-13788

Immediate actions

  • Update Google Chrome to 150.0.7871.46/47 (Windows/macOS) or 150.0.7871.46 (Linux) or later, which supersedes the 149.0.7827.53/54 line and includes all 811+ individually-tracked CVE fixes plus the broader 1,072-bug AI-assisted fix set
  • Verify auto-update is enabled and unblocked by policy — Chrome is piloting two security releases per week plus 'dynamic patching' (background hot-swap without a full restart), so environments pinning/delaying updates will widen their exposure window relative to Chrome's own release cadence
  • Enforce a minimum-Chrome-version compliance policy via endpoint/browser management given the scale of Critical fixes (22 in Chrome 149, 15 in Chrome 150) shipped in consecutive milestones

Workarounds

  • No workaround substitutes for patching to the current stable channel; where immediate update is not possible, prioritize disabling or restricting use of the most-affected components in this cycle (ANGLE/WebGL, Network stack, Extensions, GPU process, Bluetooth, WebUSB) and ensure site-isolation/sandbox enforcement is not disabled by enterprise policy

Longer-term hardening

  • Track Google's shift to twice-weekly Chrome security releases and adjust internal patch-management SLAs and change-control windows accordingly
  • For teams maintaining Chromium-embedded (CEF) or Electron-based products, monitor Big Sleep and CodeMender upstream disclosures (Project Zero / Google DeepMind) for findings relevant to the embedded engine version in use
  • Evaluate whether internal AppSec/vulnerability-management pipelines could adopt an analogous LLM-assisted triage pipeline (dedup, reproduction, severity, routing) to reduce the reported 5-30+ minute manual analyst time per report

CVEs associated with Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072

CVE-2026-10881, CVE-2026-10882

Weaknesses (CWE) in Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072

CWE-125, CWE-787, CWE-416

Timeline of Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072

  • Google begins incorporating LLMs into Chrome's OSS-Fuzz-based security fuzzing pipeline (year-level date per BleepingComputer timeline reporting).
  • Google DeepMind launches CodeMender, an AI agent for code security, in preview — combining Gemini Deep Think reasoning with static/dynamic analysis, fuzzing, differential testing, and SMT solvers.
  • A Gemini-powered agent harness is deployed for Chrome vulnerability triage, using a knowledge base of Chrome's Git history and prior CVEs (early-2026 date per BleepingComputer timeline).
  • Chrome Vulnerability Reward Program report volume for March 2026 alone surpasses the program's entire 2025 annual total.
  • 16 vulnerabilities in a Chrome release are attributed to internal Google discovery as the AI-assisted pipeline ramps up (SecurityWeek timeline).
  • 21 vulnerabilities are attributed to internal Google discovery in the next release cycle.
  • Google internally discovers 100 vulnerabilities in a single release cycle, the sharpest jump in the AI-driven discovery ramp-up.
  • Google's AI tooling blocks more than 20 vulnerabilities from reaching production in May 2026, including one critical S1+-severity issue, before any release shipped.
  • CSOonline reports Google folding CodeMender into the Gemini Enterprise Agent Platform (identity, gateway, and observability integration) for broader enterprise AppSec adoption; analysts flag governance/visibility gaps around autonomous remediation.
  • Chrome 149 (149.0.7827.53/54) ships, fixing 429 security bugs including 22 Critical CVEs (CVE-2026-10881 through CVE-2026-10902) — among them CVE-2026-10881, a Big Sleep-linked ANGLE out-of-bounds sandbox-escape (CVSS 9.6), and CVE-2026-10882, a Network use-after-free enabling remote code execution (CVSS 8.8).
  • Chrome 150 (150.0.7871.46/47) ships, fixing 382 security bugs including 15 Critical CVEs (CVE-2026-13774 through CVE-2026-13788), predominantly use-after-free flaws across Extensions, GPU, Browser, Bluetooth, WebUSB, Views, Chromoting, and Ozone; none reported as actively exploited in the wild.
  • Google's Chrome Security Team publishes 'Stronger with every update,' disclosing that Chrome 149 and 150 combined fixed 1,072 security bugs (more than the prior 23 releases combined) via the Big Sleep/CodeMender/Gemini pipeline, and revealing discovery of a 13-year-old ANGLE-area sandbox-escape bug (crbug.com/487383169) that let a compromised renderer read local files.
  • Cyber Security News publishes coverage of Google's AI-driven Chrome vulnerability findings, the article that triggered this hunt record.

Sources cited for Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072

Detection coverage for TL-2026-1795

As of 2026-07-31, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1795 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
24 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats