Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072 Chrome Security Bugs Across Chrome 149/150, Including 13-Year-Old ANGLE Sandbox-Escape (CVE-2026-10881) — Threadlinqs Intelligence
As of 2026-07-31, Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072 Chrome Security Bugs Across Chrome 149/150, Including 13-Year-Old ANGLE Sandbox-Escape (CVE-2026-10881) is a info-severity threat intel threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-1795 · Severity: INFO · Status: ACTIVE · Category: THREAT_INTEL
Google's Chrome Security Team, working with Google DeepMind and Project Zero, reports that a Gemini-powered agent framework combined with the Big Sleep vulnerability-discovery agent and the CodeMender
This is a defensive-tooling/threat-intel research signal, not an exploited threat: Google has no report of active exploitation, threat-actor involvement, or a single CVSS-scored vulnerability driving this record. Instead it documents a structural shift in how Chrome's security bugs are found, triaged, and patched, disclosed by Google's Chrome Security Team in the July 30, 2026 post 'Stronger with every update: How we're making Chrome and the web safer in the AI Era' (blog.google/security/chrome-stronger-with-every-update/).
Google built a custom agent harness on Gemini (and other models) with a knowledge base covering Chrome's full Git history, all previously identified CVEs, and per-component SECURITY.md trust-boundary documentation. The harness runs a four-phase triage pipeline: (1) filtering spam/duplicate reports, (2) reproducing the bug with stack traces on affected OS/browser versions, (3) enriching metadata (bug-introduction timeline, severity rating), and (4) automatically routing the bug to the correct human component owner. A separate multi-agent fixing workflow uses a 'fixing agent' to generate candidate patches, a 'critic agent' to evaluate them, and 'test-writing agents' to produce platform-agnostic regression tests before human engineer review — humans remain the final approver; no patch is auto-committed.
Two DeepMind/Project Zero tools are integrated directly into Chrome's continuous-integration pipeline, running every 24 hours across all code changes: Big Sleep (an AI vulnerability-discovery agent, successor lineage to the earlier Project Zero 'Naptime' framework, that has found bugs in the V8 JavaScript engine and Chrome's graphics stack) and CodeMender (a DeepMind AI agent, launched in preview around October 2025, that uses Gemini Deep Think reasoning plus static analysis, dynamic analysis, differential testing, fuzzing, and SMT solvers to find root causes and generate validated patches — it has upstreamed 72 security fixes to open-source projects, including complex object-lifetime fixes and `-fbounds-safety` annotations added to the libwebp image library, across codebases as large as 4.5 million lines). As of May 2026, Google is folding CodeMender into its Gemini Enterprise Agent Platform for broader enterprise AppSec use (with identity/gateway/observability integration); analysts such as Chris Steffen (VP, Enterprise Management Associates) have flagged that enterprises will want governance controls and visibility into false-positive/regression rates before trusting autonomous remediation as a point solution.
The headline discovery cited by Google is a sandbox-escape vulnerability (tracked at crbug.com/487383169 / issues.chromium.org/issues/487383169) that had persisted in Chrome's codebase for more than 13 years, which would let a compromised renderer process trick the browser into reading local files outside its sandbox boundary. Separately, and independently confirmed via NVD, Chrome 149 (149.0.7827.53/54 for Windows/macOS, 149.0.7827.53 for Linux; released 2026-06-04) fixed 429 security bugs — 22 of them Critical, reported as CVE-2026-10881 through CVE-2026-10902 — including CVE-2026-10881 (out-of-bounds read/write in ANGLE, CVSS 3.1 9.6 Critical, CWE-125/CWE-787, sandbox escape via a crafted HTML page) and CVE-2026-10882 (use-after-free in Network, CVSS 3.1 8.8 High, CWE-416, remote code execution via a crafted HTML page). Chrome 150 (150.0.7871.46/47 Windows/macOS, 150.0.7871.46 Linux; released 2026-06-30) fixed 382 security bugs, 15 of them Critical (reported as CVE-2026-13774 through CVE-2026-13788), predominantly use-after-free flaws across Extensions, GPU, Browser, Bluetooth, WebUSB, Views, Chromoting, and Ozone components. Neither the Chrome 149 nor Chrome 150 critical CVEs appear in the CISA Known Exploited Vulnerabilities catalog as of this record — press reporting states none of the patched Chrome 150 issues were known to be actively exploited in the wild.
Google also reports that in May 2
Weaknesses (CWE)
CWE-125, CWE-787, CWE-416
Target sectors: technology, government administration, financial-services, health, critical-infrastructure, education, retail
Target regions: Global
Detections & IOCs
As of 2026-08-09, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, INFO, threat intelligence, cybersecurity, CVE-2026-10881, CVE-2026-10882, T1596, T1588, T1587, T1189, T1203, T1204, T1059, T1176, T1068, T1211