Friday, September 11, 2026

Critical Chrome Use-After-Free Flaw Enables Arbitrary Code Execution

Google has released an urgent security update for the Chrome Stable channel to address a critical use-after-free vulnerability in the ANGLE graphics library that could allow attackers to execute arbitrary code on vulnerable systems.

The fixes arrive as part of Chrome Stable versions 139.0.7258.154/.155 on Windows and macOS, and 139.0.7258.154 on Linux. Users are advised to update immediately, as the patch will roll out automatically over the coming days and weeks.

Background and Impact

The flaw, tracked as CVE-2025-9478, was discovered by the Google Big Sleep team on August 11, 2025. It resides in the ANGLE component, which translates OpenGL ES calls to native graphics API calls on various platforms.

A malicious website exploiting this vulnerability could trigger a use-after-free condition, whereby memory is reused after being freed.

By carefully crafting WebGL or Canvas operations, an attacker could corrupt the browser’s memory and achieve remote code execution with the privileges of the current user.

CVE IDSeverityDescriptionReported Date
CVE-2025-9478CriticalUse-after-free leading to code exec2025-08-11

Given ANGLE’s central role in Chrome’s rendering pipeline across desktop and mobile platforms, exploitation could be scripted in a drive-by download scenario: a victim simply needs to visit a compromised or maliciously crafted webpage.

Successful exploitation may allow attackers to install malware, steal data, or pivot deeper into a corporate network, making this flaw especially dangerous for high-value targets and enterprise users.

Mitigation and Recommendations

Google’s security team has already deployed the fix in the latest Stable builds. Administrators managing large deployments should ensure that version 139.0.7258.154/.155 is pushed without delay.

For organizations with strict change management procedures, Chrome’s enterprise bundle and MSI installers are available to facilitate offline or staged rollouts.

In addition to updating Chrome, security teams should:

  • Monitor proxy and endpoint logs for unusual WebGL or graphics API call patterns.
  • Enforce principle of least privilege to limit the impact of a compromised browser process.
  • Educate users about the dangers of visiting untrusted websites, especially those that host WebGL content.

Google continues to support collaborative discovery by offering rewards for externally reported bugs.

 While details of CVE-2025-9478 remain restricted until the majority of users receive the fix, the acknowledgment of the external researcher underscores the value of public–private partnerships in securing open-source projects.

Find this News Interesting! Follow us on Google NewsLinkedIn, and X to Get Instant Updates!

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

OpenMatter Network Realigns Leadership Team to Accelerate Global Commercial Growth

Melbourne, Florida, September 10th, 2026, CyberNewswire With its Verification Architecture...

Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft

Nearly one in 10 internet-exposed LiteLLM AI gateways accepted...

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

Skullcandy Dime 3 wireless earbuds have a serious vulnerability...

Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly

Threat actors are increasingly exploiting Active Directory replication mechanisms...

Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers

Threat actors are exploiting anticipation around Grand Theft Auto...

Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds

A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O...

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

Palo Alto Networks has announced a high-severity buffer overflow...

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out...

Related Articles

Recent News