In The Same Week, Google Shipped Chrome 149 With Patches For A Record 429 Security Bugs; Over 100 Of Them Critical Or High Severity, With The Worst Carrying A CVSS Score Of 9.6 And Allowing A Crafted Web Page To Escape The Browser Sandbox Entirely
According to The Hacker News and depthfirst, an autonomous AI security agent scanned FFmpeg’s approximately 1.5 million lines of C code and produced 21 confirmed zero-days, each with a reproducible proof-of-concept exploit.
The entire run cost approximately $1,000. Several of the vulnerabilities had been dormant for 15 to 20 years; one stack overflow in the service-description-table parser dates to 2003 and remained undetected for 23 years.
Most are heap or stack overflows in demuxers and parsers, spanning components from the TS demuxer to the VP9 decoder. Nine have been assigned CVE identifiers, CVE-2026-39210 through CVE-2026-39218.
In separate but directly related news, Google shipped Chrome 149 with patches for 429 security vulnerabilities; the most ever fixed in a single Chrome release. Over 100 are rated critical or high severity.
The worst, CVE-2026-10881, carries a CVSS score of 9.6: an out-of-bounds read and write in Chrome’s ANGLE graphics engine that allows a crafted web page to escape the browser sandbox and execute arbitrary code on the host. Google paid the external researcher $97,000 for the report.
Google overhauled its vulnerability reward programme in April 2026 specifically to cope with a flood of AI-generated bug reports, requesting concise reproducers rather than the long written analyses AI systems generate automatically.
FFmpeg users should prioritise patching all upstream fixes immediately. Chrome should be updated to version 149.0.7827.53. To check out our previous coverage on cybersecurity, AI vulnerability research, and zero-days, read our articles here.

