# Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072 Chrome Security Bugs Across Chrome 149/150, Including 13-Year-Old ANGLE Sandbox-Escape (CVE-2026-10881)

> Google's Chrome Security Team, working with Google DeepMind and Project Zero, reports that a Gemini-powered agent framework combined with the Big Sleep vulnerability-discovery agent and the CodeMender code-security agent drove Chrome 149 and Chrome 150 to fix 1,072 security bugs combined — more than the prior 23 stable releases combined — including a 13-year-old ANGLE sandbox-escape bug (crbug.com/487383169) that could let a compromised renderer read local files, and blocked over 20 vulnerabilities from reaching production in May 2026 alone, including one critical S1+ issue.

- **Published:** 2026-07-31T00:00:00Z
- **Last reviewed:** 2026-07-31T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1795
- **ID:** TL-2026-1795
- **Severity:** INFO
- **Category:** THREAT_INTEL
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 24 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-10881, CVE-2026-10882

## Description

This is a defensive-tooling/threat-intel research signal, not an exploited threat: Google has no report of active exploitation, threat-actor involvement, or a single CVSS-scored vulnerability driving this record. Instead it documents a structural shift in how Chrome's security bugs are found, triaged, and patched, disclosed by Google's Chrome Security Team in the July 30, 2026 post 'Stronger with every update: How we're making Chrome and the web safer in the AI Era' (blog.google/security/chrome-stronger-with-every-update/).

Google built a custom agent harness on Gemini (and other models) with a knowledge base covering Chrome's full Git history, all previously identified CVEs, and per-component SECURITY.md trust-boundary documentation. The harness runs a four-phase triage pipeline: (1) filtering spam/duplicate reports, (2) reproducing the bug with stack traces on affected OS/browser versions, (3) enriching metadata (bug-introduction timeline, severity rating), and (4) automatically routing the bug to the correct human component owner. A separate multi-agent fixing workflow uses a 'fixing agent' to generate candidate patches, a 'critic agent' to evaluate them, and 'test-writing agents' to produce platform-agnostic regression tests before human engineer review — humans remain the final approver; no patch is auto-committed.

Two DeepMind/Project Zero tools are integrated directly into Chrome's continuous-integration pipeline, running every 24 hours across all code changes: Big Sleep (an AI vulnerability-discovery agent, successor lineage to the earlier Project Zero 'Naptime' framework, that has found bugs in the V8 JavaScript engine and Chrome's graphics stack) and CodeMender (a DeepMind AI agent, launched in preview around October 2025, that uses Gemini Deep Think reasoning plus static analysis, dynamic analysis, differential testing, fuzzing, and SMT solvers to find root causes and generate validated patches — it has upstreamed 72 security fixes to open-source projects, including complex object-lifetime fixes and `-fbounds-safety` annotations added to the libwebp image library, across codebases as large as 4.5 million lines). As of May 2026, Google is folding CodeMender into its Gemini Enterprise Agent Platform for broader enterprise AppSec use (with identity/gateway/observability integration); analysts such as Chris Steffen (VP, Enterprise Management Associates) have flagged that enterprises will want governance controls and visibility into false-positive/regression rates before trusting autonomous remediation as a point solution.

The headline discovery cited by Google is a sandbox-escape vulnerability (tracked at crbug.com/487383169 / issues.chromium.org/issues/487383169) that had persisted in Chrome's codebase for more than 13 years, which would let a compromised renderer process trick the browser into reading local files outside its sandbox boundary. Separately, and independently confirmed via NVD, Chrome 149 (149.0.7827.53/54 for Windows/macOS, 149.0.7827.53 for Linux; released 2026-06-04) fixed 429 security bugs — 22 of them Critical, reported as CVE-2026-10881 through CVE-2026-10902 — including CVE-2026-10881 (out-of-bounds read/write in ANGLE, CVSS 3.1 9.6 Critical, CWE-125/CWE-787, sandbox escape via a crafted HTML page) and CVE-2026-10882 (use-after-free in Network, CVSS 3.1 8.8 High, CWE-416, remote code execution via a crafted HTML page). Chrome 150 (150.0.7871.46/47 Windows/macOS, 150.0.7871.46 Linux; released 2026-06-30) fixed 382 security bugs, 15 of them Critical (reported as CVE-2026-13774 through CVE-2026-13788), predominantly use-after-free flaws across Extensions, GPU, Browser, Bluetooth, WebUSB, Views, Chromoting, and Ozone components. Neither the Chrome 149 nor Chrome 150 critical CVEs appear in the CISA Known Exploited Vulnerabilities catalog as of this record — press reporting states none of the patched Chrome 150 issues were known to be actively exploited in the wild.

Google also reports that in May 2026 the AI pipeline blocked more than 20 vulnerabilities from ever reaching a production release, including one critical S1+-severity issue, and that Chrome Vulnerability Reward Program report volume for March 2026 alone exceeded the program's entire 2025 annual total (16, then 21, then 100 vulnerabilities attributed to internal Google discovery across successive April/May 2026 releases, per SecurityWeek's tracking). The trend is cross-vendor: SecurityWeek reports Mozilla found 270+ Firefox vulnerabilities using Anthropic's 'Claude Mythos' model (available to roughly 50 organizations including Google), and that Microsoft and Palo Alto Networks are finding vulnerabilities with their own internal AI tooling. Google frames the resulting spike in disclosed bug counts as improved detection, not a decline in Chrome's underlying security, and is simultaneously piloting faster patch delivery — two security releases per week and 'dynamic patching' to hot-swap background browser processes without a full restart — to shrink the patch gap that a faster AI-driven discovery rate would otherwise widen. Longer-running Chrome memory-safety investments referenced alongside this effort include MiraclePtr/MiracleObject (use-after-free mitigation), the Spanification project (97% of first-party Chrome code compiles cleanly under strict unsafe-buffer/std::span warnings), checked-math integer-overflow protection, ongoing Rust migration of memory-unsafe components, and GOSSIP (Google's Open Source Security Intelligence Platform) for supply-chain risk scoring across Chrome's 2,300+ third-party dependencies (~1,700 shipped to users).

No IOCs, threat-actor attribution, or exploitation-in-the-wild are asserted anywhere in the sourced reporting; this record exists to give defenders visibility into Google's AI-augmented vulnerability-management pipeline, the specific CVEs it has already produced and patched, and the broader industry trend of LLM-driven vulnerability discovery/remediation that is materially increasing disclosed bug volume across major browser vendors.

## MITRE ATT&CK

- T1596 Search Open Technical Databases
- T1588 Obtain Capabilities
- T1587 Develop Capabilities
- T1189 Drive-by Compromise
- T1203 Exploitation for Client Execution
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1176 Software Extensions
- T1068 Exploitation for Privilege Escalation
- T1211 Exploitation for Stealth
- T1552 Unsecured Credentials
- T1539 Steal Web Session Cookie
- T1592 Gather Victim Host Information
- T1518 Software Discovery
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1041 Exfiltration Over C2 Channel

## Sources

- [Google Uses AI Agents to Find and Fix 1,072 Chrome Security Vulnerabilities](https://cybersecuritynews.com/google-ai-fixes-chrome-vulnerabilities/)
- [Stronger with every update: How we're making Chrome and the web safer in the AI Era](https://blog.google/security/chrome-stronger-with-every-update/)
- [Introducing CodeMender: an AI agent for code security](https://deepmind.google/blog/introducing-codemender-an-ai-agent-for-code-security/)
- [CodeMender: AI Agent for Code Security](https://cloud.google.com/security/codemender)
- [Google says AI helped Chrome fix 1,072 security bugs in two releases](https://www.bleepingcomputer.com/news/google/google-says-ai-helped-chrome-fix-1-072-security-bugs-in-two-releases/)
- [Chrome 149 fixes 429 security flaws, the most ever in one update](https://www.pcworld.com/article/3158038/chrome-149-fixes-429-security-flaws-the-most-ever-in-one-update.html)
- [Chrome 150 fixes nearly 400 security flaws, including 15 critical ones](https://www.pcworld.com/article/3182088/chrome-150-fixes-nearly-400-security-flaws-including-15-critical-ones.html)
- [Google's Surge in Chrome Vulnerability Discoveries Likely Driven by AI](https://www.securityweek.com/googles-surge-in-chrome-vulnerability-discoveries-likely-driven-by-ai/)
- [Google folds CodeMender into agent ecosystem amid push for AI-led AppSec](https://www.csoonline.com/article/4176164/google-folds-codemender-into-agent-ecosystem-amid-push-for-ai-led-appsec.html)
- [Google is rebuilding Chrome security using AI to catch hidden vulnerabilities](https://www.androidauthority.com/google-chrome-ai-security-overhaul-3692872/)
- [AI takes on a bigger role in finding Chrome vulnerabilities](https://www.helpnetsecurity.com/2026/07/30/google-chrome-ai-security-workflow/)
- [Google wants to update Chrome without a full browser restart](https://9to5google.com/2026/07/30/chrome-security-ai-llm/)
- [NVD - CVE-2026-10881](https://nvd.nist.gov/vuln/detail/CVE-2026-10881)
- [NVD - CVE-2026-10882](https://nvd.nist.gov/vuln/detail/CVE-2026-10882)
- [Google Chrome Critical Sandbox Escape Vulnerabilities in ANGLE and Network Components — CVE-2026-10881, CVE-2026-10882](https://techjacksolutions.com/scc-intel/google-chrome-critical-sandbox-escape-vulnerabilities-in-angle-and-network-components-cve-2026-10881-cve-2026-10882/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1795
