Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2321 articles · 160680 vulns · 36/41 feeds (7d)
← Back to list
9.6
CVE-2026-10881EXPLOITEDPATCHED
google · chrome

CVE-2026-10881: Out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially p

Description

Remote attackers could exploit the vulnerability to escape Chrome’s sandbox via crafted HTML pages, potentially achieving code execution on the underlying operating system.

Affected Products

VendorProductVersions
googlechrome149.0.7827.53

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
applemacoscve_cpe95%
googlechromecert_advisory90%
linuxlinux_kernelcve_cpe95%
microsoftedgecert_advisory90%
microsoftwindowscve_cpe95%

References

  • https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop.html
  • https://issues.chromium.org/issues/498904293

Related News (4 articles)

Tier D
SecurityWeek2d ago
Chrome 149 Patches 429 Vulnerabilities
→ No new info (linked only)
Tier B
BSI Advisories2d ago
[NEU] [hoch] Google Chrome und Microsoft Edge: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
Heise Security2d ago
Google Chrome: Update schließt 429 Sicherheitslücken
→ No new info (linked only)
Tier B
CERT-FR2d ago
Multiples vulnérabilités dans Google Chrome (05 juin 2026)
→ No new info (linked only)
CVSS 3.19.6 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
149.0.7827.53
PublishedJun 4, 2026
Last enriched2d agov2
Trending Score53
Source articles4
Independent4
Info Completeness9/14
Missing: epss, cwe, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2025-48595EXP
CVE-2025-48595: In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to
Trending: 98
HIGHCVE-2026-11255EXP
CVE-2026-11255: Insufficient validation of untrusted input in Storage Access API in Google Chrome prior to 149.0.7827.53 allowed a remot
Trending: 51
CRITICALCVE-2026-11070EXP
CVE-2026-11070: Insufficient validation of untrusted input in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a re
Trending: 50
CRITICALCVE-2026-10946EXP
CVE-2026-10946: Heap buffer overflow in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to
Trending: 50
CRITICALCVE-2026-11082EXP
CVE-2026-11082: Race in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the rendere
Trending: 50

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 4, 2026
Discovered by ZDM
Jun 4, 2026
Actively Exploited
Jun 5, 2026
Exploit Available
Jun 5, 2026
Patch Available
Jun 5, 2026
Updated: description, exploitAvailable, activelyExploited
Jun 5, 2026

Version History

v2
Last enriched 2d ago
v2Tier D2d ago

Updated description with more technical detail, marked exploit as available, and noted that the vulnerability is actively exploited.

descriptionexploitAvailableactivelyExploited
via SecurityWeek
v12d ago

Initial creation