Threat reportThreat IntelligenceTL-2026-1795
Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072 Chrome Security Bugs Across Chrome 149/150, Including 13-Year-Old ANGLE Sandbox-Escape (CVE-2026-10881)
Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072 (TL-2026-1795), also tracked as Chrome AI Security Overhaul, is a info-severity tracked intrusion set, first published 2026-07-31. It has no confirmed attribution, affects Google Google Chrome, references 2 CVEs (CVE-2026-10881, CVE-2026-10882), maps to 17 MITRE ATT&CK techniques (T1005, T1041, T1059), and is covered by 9 detection rules and 24 indicators of compromise.
- Severity
- INFOAssessed severity
- CVEs
- 2Referenced vulnerabilities
- Techniques
- 17MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 24Indicators of compromise
Key facts for TL-2026-1795
- Threat ID
- TL-2026-1795
- Also known as
- Chrome AI Security Overhaul, Chrome 1,072-bug AI patching wave
- Severity
- INFO
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, government administration, financial-services, health, critical-infrastructure, education, retail
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072
Malware and tooling: Big Sleep, Claude Mythos, CodeMender, GOSSIP, Gemini Deep Think, MiraclePtr, Naptime, OSS-Fuzz
How Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072 works
Google's Chrome Security Team, working with Google DeepMind and Project Zero, reports that a Gemini-powered agent framework combined with the Big Sleep vulnerability-discovery agent and the CodeMender code-security agent drove Chrome 149 and Chrome 150 to fix 1,072 security bugs combined — more than the prior 23 stable releases combined — including a 13-year-old ANGLE sandbox-escape bug (crbug.com/487383169) that could let a compromised renderer read local files, and blocked over 20 vulnerabilities from reaching production in May 2026 alone, including one critical S1+ issue.
This is a defensive-tooling/threat-intel research signal, not an exploited threat: Google has no report of active exploitation, threat-actor involvement, or a single CVSS-scored vulnerability driving this record. Instead it documents a structural shift in how Chrome's security bugs are found, triaged, and patched, disclosed by Google's Chrome Security Team in the July 30, 2026 post 'Stronger with every update: How we're making Chrome and the web safer in the AI Era' (blog.google/security/chrome-stronger-with-every-update/).
Google built a custom agent harness on Gemini (and other models) with a knowledge base covering Chrome's full Git history, all previously identified CVEs, and per-component SECURITY.md trust-boundary documentation. The harness runs a four-phase triage pipeline: (1) filtering spam/duplicate reports, (2) reproducing the bug with stack traces on affected OS/browser versions, (3) enriching metadata (bug-introduction timeline, severity rating), and (4) automatically routing the bug to the correct human component owner. A separate multi-agent fixing workflow uses a 'fixing agent' to generate candidate patches, a 'critic agent' to evaluate them, and 'test-writing agents' to produce platform-agnostic regression tests before human engineer review — humans remain the final approver; no patch is auto-committed.
Two DeepMind/Project Zero tools are integrated directly into Chrome's continuous-integration pipeline, running every 24 hours across all code changes: Big Sleep (an AI vulnerability-discovery agent, successor lineage to the earlier Project Zero 'Naptime' framework, that has found bugs in the V8 JavaScript engine and Chrome's graphics stack) and CodeMender (a DeepMind AI agent, launched in preview around October 2025, that uses Gemini Deep Think reasoning plus static analysis, dynamic analysis, differential testing, fuzzing, and SMT solvers to find root causes and generate validated patches — it has upstreamed 72 security fixes to open-source projects, including complex object-lifetime fixes and `-fbounds-safety` annotations added to the libwebp image library, across codebases as large as 4.5 million lines). As of May 2026, Google is folding CodeMender into its Gemini Enterprise Agent Platform for broader enterprise AppSec use (with identity/gateway/observability integration); analysts such as Chris Steffen (VP, Enterprise Management Associates) have flagged that enterprises will want governance controls and visibility into false-positive/regression rates before trusting autonomous remediation as a point solution.
The headline discovery cited by Google is a sandbox-escape vulnerability (tracked at crbug.com/487383169 / issues.chromium.org/issues/487383169) that had persisted in Chrome's codebase for more than 13 years, which would let a compromised renderer process trick the browser into reading local files outside its sandbox boundary. Separately, and independently confirmed via NVD, Chrome 149 (149.0.7827.53/54 for Windows/macOS, 149.0.7827.53 for Linux; released 2026-06-04) fixed 429 security bugs — 22 of them Critical, reported as CVE-2026-10881 through CVE-2026-10902 — including CVE-2026-10881 (out-of-bounds read/write in ANGLE, CVSS 3.1 9.6 Critical, CWE-125/CWE-787, sandbox escape via a crafted HTML page) and CVE-2026-10882 (use-after-free in Network, CVSS 3.1 8.8 High, CWE-416, remote code execution via a crafted HTML page). Chrome 150 (150.0.7871.46/47 Windows/macOS, 150.0.7871.46 Linux; released 2026-06-30) fixed 382 security bugs, 15 of them Critical (reported as CVE-2026-13774 through CVE-2026-13788), predominantly use-after-free flaws across Extensions, GPU, Browser, Bluetooth, WebUSB, Views, Chromoting, and Ozone components. Neither the Chrome 149 nor Chrome 150 critical CVEs appear in the CISA Known Exploited Vulnerabilities catalog as of this record — press reporting states none of the patched Chrome 150 issues were known to be actively exploited in the wild.
Google also reports that in May 2026 the AI pipeline blocked more than 20 vulnerabilities from ever reaching a production release, including one critical S1+-severity issue, and that Chrome Vulnerability Reward Program report volume for March 2026 alone exceeded the program's entire 2025 annual total (16, then 21, then 100 vulnerabilities attributed to internal Google discovery across successive April/May 2026 releases, per SecurityWeek's tracking). The trend is cross-vendor: SecurityWeek reports Mozilla found 270+ Firefox vulnerabilities using Anthropic's 'Claude Mythos' model (available to roughly 50 organizations including Google), and that Microsoft and Palo Alto Networks are finding vulnerabilities with their own internal AI tooling. Google frames the resulting spike in disclosed bug counts as improved detection, not a decline in Chrome's underlying security, and is simultaneously piloting faster patch delivery — two security releases per week and 'dynamic patching' to hot-swap background browser processes without a full restart — to shrink the patch gap that a faster AI-driven discovery rate would otherwise widen. Longer-running Chrome memory-safety investments referenced alongside this effort include MiraclePtr/MiracleObject (use-after-free mitigation), the Spanification project (97% of first-party Chrome code compiles cleanly under strict unsafe-buffer/std::span warnings), checked-math integer-overflow protection, ongoing Rust migration of memory-unsafe components, and GOSSIP (Google's Open Source Security Intelligence Platform) for supply-chain risk scoring across Chrome's 2,300+ third-party dependencies (~1,700 shipped to users).
No IOCs, threat-actor attribution, or exploitation-in-the-wild are asserted anywhere in the sourced reporting; this record exists to give defenders visibility into Google's AI-augmented vulnerability-management pipeline, the specific CVEs it has already produced and patched, and the broader industry trend of LLM-driven vulnerability discovery/remediation that is materially increasing disclosed bug volume across major browser vendors.
MITRE ATT&CK techniques used in TL-2026-1795
Collection
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution; T1204 User Execution
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Command and Control
T1071 Application Layer Protocol
Persistence
Initial Access
Defense Evasion
T1211 Exploitation for Stealth
Discovery
Credential Access
T1539 Steal Web Session Cookie; T1552 Unsecured Credentials
Resource Development
T1587 Develop Capabilities; T1588 Obtain Capabilities
reconnaissance
T1592 Gather Victim Host Information
Reconnaissance
Affected products and versions in Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072
- Google — Google Chrome
Vulnerable versions: prior to 149.0.7827.53 (Linux); prior to 149.0.7827.53/54 (Windows/macOS)
Fixed in: 149.0.7827.53 (Linux); 149.0.7827.53/54 (Windows/macOS) - Google — Google Chrome
Vulnerable versions: prior to 150.0.7871.46 (Linux); prior to 150.0.7871.46/47 (Windows/macOS)
Fixed in: 150.0.7871.46 (Linux); 150.0.7871.46/47 (Windows/macOS)
Remediation for Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072
Patches
- Chrome 149 (149.0.7827.53/54 Windows/macOS, 149.0.7827.53 Linux, released 2026-06-04) — 429 security fixes including 22 Critical CVEs reported as CVE-2026-10881 through CVE-2026-10902
- Chrome 150 (150.0.7871.46/47 Windows/macOS, 150.0.7871.46 Linux, released 2026-06-30) — 382 security fixes including 15 Critical CVEs reported as CVE-2026-13774 through CVE-2026-13788
Immediate actions
- Update Google Chrome to 150.0.7871.46/47 (Windows/macOS) or 150.0.7871.46 (Linux) or later, which supersedes the 149.0.7827.53/54 line and includes all 811+ individually-tracked CVE fixes plus the broader 1,072-bug AI-assisted fix set
- Verify auto-update is enabled and unblocked by policy — Chrome is piloting two security releases per week plus 'dynamic patching' (background hot-swap without a full restart), so environments pinning/delaying updates will widen their exposure window relative to Chrome's own release cadence
- Enforce a minimum-Chrome-version compliance policy via endpoint/browser management given the scale of Critical fixes (22 in Chrome 149, 15 in Chrome 150) shipped in consecutive milestones
Workarounds
- No workaround substitutes for patching to the current stable channel; where immediate update is not possible, prioritize disabling or restricting use of the most-affected components in this cycle (ANGLE/WebGL, Network stack, Extensions, GPU process, Bluetooth, WebUSB) and ensure site-isolation/sandbox enforcement is not disabled by enterprise policy
Longer-term hardening
- Track Google's shift to twice-weekly Chrome security releases and adjust internal patch-management SLAs and change-control windows accordingly
- For teams maintaining Chromium-embedded (CEF) or Electron-based products, monitor Big Sleep and CodeMender upstream disclosures (Project Zero / Google DeepMind) for findings relevant to the embedded engine version in use
- Evaluate whether internal AppSec/vulnerability-management pipelines could adopt an analogous LLM-assisted triage pipeline (dedup, reproduction, severity, routing) to reduce the reported 5-30+ minute manual analyst time per report
CVEs associated with Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072
Weaknesses (CWE) in Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072
Timeline of Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072
- Google begins incorporating LLMs into Chrome's OSS-Fuzz-based security fuzzing pipeline (year-level date per BleepingComputer timeline reporting).
- Google DeepMind launches CodeMender, an AI agent for code security, in preview — combining Gemini Deep Think reasoning with static/dynamic analysis, fuzzing, differential testing, and SMT solvers.
- A Gemini-powered agent harness is deployed for Chrome vulnerability triage, using a knowledge base of Chrome's Git history and prior CVEs (early-2026 date per BleepingComputer timeline).
- Chrome Vulnerability Reward Program report volume for March 2026 alone surpasses the program's entire 2025 annual total.
- 16 vulnerabilities in a Chrome release are attributed to internal Google discovery as the AI-assisted pipeline ramps up (SecurityWeek timeline).
- 21 vulnerabilities are attributed to internal Google discovery in the next release cycle.
- Google internally discovers 100 vulnerabilities in a single release cycle, the sharpest jump in the AI-driven discovery ramp-up.
- Google's AI tooling blocks more than 20 vulnerabilities from reaching production in May 2026, including one critical S1+-severity issue, before any release shipped.
- CSOonline reports Google folding CodeMender into the Gemini Enterprise Agent Platform (identity, gateway, and observability integration) for broader enterprise AppSec adoption; analysts flag governance/visibility gaps around autonomous remediation.
- Chrome 149 (149.0.7827.53/54) ships, fixing 429 security bugs including 22 Critical CVEs (CVE-2026-10881 through CVE-2026-10902) — among them CVE-2026-10881, a Big Sleep-linked ANGLE out-of-bounds sandbox-escape (CVSS 9.6), and CVE-2026-10882, a Network use-after-free enabling remote code execution (CVSS 8.8).
- Chrome 150 (150.0.7871.46/47) ships, fixing 382 security bugs including 15 Critical CVEs (CVE-2026-13774 through CVE-2026-13788), predominantly use-after-free flaws across Extensions, GPU, Browser, Bluetooth, WebUSB, Views, Chromoting, and Ozone; none reported as actively exploited in the wild.
- Google's Chrome Security Team publishes 'Stronger with every update,' disclosing that Chrome 149 and 150 combined fixed 1,072 security bugs (more than the prior 23 releases combined) via the Big Sleep/CodeMender/Gemini pipeline, and revealing discovery of a 13-year-old ANGLE-area sandbox-escape bug (crbug.com/487383169) that let a compromised renderer read local files.
- Cyber Security News publishes coverage of Google's AI-driven Chrome vulnerability findings, the article that triggered this hunt record.
Sources cited for Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072
- Google Uses AI Agents to Find and Fix 1,072 Chrome Security Vulnerabilities
- Stronger with every update: How we're making Chrome and the web safer in the AI Era
- Introducing CodeMender: an AI agent for code security
- CodeMender: AI Agent for Code Security
- Google says AI helped Chrome fix 1,072 security bugs in two releases
- Chrome 149 fixes 429 security flaws, the most ever in one update
- Chrome 150 fixes nearly 400 security flaws, including 15 critical ones
- Google's Surge in Chrome Vulnerability Discoveries Likely Driven by AI
- Google folds CodeMender into agent ecosystem amid push for AI-led AppSec
- Google is rebuilding Chrome security using AI to catch hidden vulnerabilities
- AI takes on a bigger role in finding Chrome vulnerabilities
- Google wants to update Chrome without a full browser restart
- NVD - CVE-2026-10881
- NVD - CVE-2026-10882
- Google Chrome Critical Sandbox Escape Vulnerabilities in ANGLE and Network Components — CVE-2026-10881, CVE-2026-10882
Detection coverage for TL-2026-1795
As of 2026-07-31, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1795 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.