Google Chrome: critical security hole in web browser
Summary
In August 2025 Google closed a critical hole in Chrome (CVE-2025-9478), a use-after-free bug in the WebGL backend ANGLE. Attackers could exploit the memory bug via prepared websites, which usually leads to the execution of malicious code. The hole was fixed in Chrome 139.0.7258.154/155; Chromium-based browsers such as Edge are likely to be affected as well.
Ideas
- Use-after-free accesses memory that has already been freed and has undefined content.
- Graphics interfaces such as WebGL extend the browser’s attack surface.
- Google only publishes details once most users have updated.
- Android users receive updates via the Play Store with a delay.
Insights
- Memory bugs in C++ code remain the main source of critical browser holes.
- Chromium holes spread to all browsers that use the same foundation.
Facts
- The hole is in ANGLE, the WebGL rendering backend.
- In mid-July 2025 Google had already had to close an actively exploited Chrome hole.
References
Critique
- Since Google gives hardly any details, the assessment regarding code execution is based on the editorial team’s assumptions.
Recommendations
- Check under “About Google Chrome” that the current version is running, and restart the browser.
- With Chromium holes, think of all derived browsers in the company, not just Chrome.
Links to the original source and the Web Archive open in a new tab.