bk99.de entertain the web since 1997

Google Chrome: critical security hole in web browser

Summary

In August 2025 Google closed a critical hole in Chrome (CVE-2025-9478), a use-after-free bug in the WebGL backend ANGLE. Attackers could exploit the memory bug via prepared websites, which usually leads to the execution of malicious code. The hole was fixed in Chrome 139.0.7258.154/155; Chromium-based browsers such as Edge are likely to be affected as well.

Ideas

  • Use-after-free accesses memory that has already been freed and has undefined content.
  • Graphics interfaces such as WebGL extend the browser’s attack surface.
  • Google only publishes details once most users have updated.
  • Android users receive updates via the Play Store with a delay.

Insights

  • Memory bugs in C++ code remain the main source of critical browser holes.
  • Chromium holes spread to all browsers that use the same foundation.

Facts

  • The hole is in ANGLE, the WebGL rendering backend.
  • In mid-July 2025 Google had already had to close an actively exploited Chrome hole.

References

Critique

  • Since Google gives hardly any details, the assessment regarding code execution is based on the editorial team’s assumptions.

Recommendations

  • Check under “About Google Chrome” that the current version is running, and restart the browser.
  • With Chromium holes, think of all derived browsers in the company, not just Chrome.

Read the original article

Search the Web Archive