CVE-2025-9478 is a critical use-after-free vulnerability in ANGLE, affecting Google Chrome prior to version 139.0.7258.154, and consequently impacting products from Apple, Google, Linux, and Microsoft. This high-severity flaw (CVSS 8.8) allows a remote unauthenticated attacker to potentially achieve heap corruption by tricking a user into visiting a crafted HTML page. While no public exploit code or active exploitation is confirmed, the vulnerability has garnered significant community discussion and media coverage, indicating its potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 139.0.7258.154, < 139.0.7258.154CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 139.0.7258.154CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.