Vulnerability intelligence
CVE-2026-10881
Out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CVSS Score
9.6
Critical
EPSS — Exploit Probability
0.4%
Riskier than 31% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
Patch available
Vendor fix published
1 article across 1 outlet · first covered Jun 5, 2026 · latest Jun 5, 2026
Coverage timeline
-
Chrome 149 Patches 429 Vulnerabilitieswww.securityweek.com · Jun 5, 2026