Overview
- Updates are available as Chrome 139.0.7258.154/.155 for Windows and macOS, 139.0.7258.154 for Linux, and 139.0.7258.158 for Android.
- CVE-2025-9478 is a use-after-free in the ANGLE WebGL backend that can be triggered by crafted HTML and may enable code execution.
- Google says it has seen no evidence of in-the-wild exploitation so far and is withholding technical details during rollout.
- The discovery is attributed to Google's Big Sleep AI; such findings are reviewed by experts, and Google has not disclosed false‑positive rates.
- Because the flaw is in Chromium, other browsers like Edge, Brave, Vivaldi and Opera require updates, with several currently behind the latest Chromium build levels.