Threat Brief — 2026-10-03: Chromium ANGLE flaw, MI5 academic exposure
Executive summary: A heap buffer overflow in Chromium's ANGLE graphics layer (CVE-2025-10502) has been disclosed via Microsoft's security update portal, warranting attention for browser-dependent environments. Separately, MI5 has revealed that British university professors unknowingly developed software for Chinese state security over several years, covering AI, cybersecurity, and covert communications — a first-time disclosure that underscores supply-chain and academic targeting risks.
Top items
- Chromium CVE-2025-10502 — heap buffer overflow in ANGLE. Microsoft has published information on a heap buffer overflow vulnerability in ANGLE (Almost Native Graphics Layer Engine), the OpenGL ES translation layer used in Chromium-based browsers. No public exploit or KEV listing is indicated in the available finding. Browser-level memory corruption flaws are common precursors to drive-by exploitation; the severity rating and patch availability are not yet detailed in the source. (src: MSRC Security Updates)
- MI5 exposes British academics who unwittingly wrote software for Chinese state security. MI5 has disclosed that UK university professors spent years developing software for Chinese state security apparatus without their knowledge. The work reportedly spanned AI, cybersecurity, and covert communications research. This is a fresh disclosure first reported today. (src: SecurityLab)
Themes
Academic and research-sector targeting. The MI5 disclosure highlights a persistent pattern of state actors using front organisations to channel sensitive research through unwitting academics. This reinforces the need for due diligence on research collaborations and funding provenance, particularly in dual-use fields such as AI and communications security.
