CVE-2025-8901Out-of-bounds Write in Google Chrome

Severity
8.8HIGHNVD
EPSS
0.1%
top 76.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 13
Latest updateAug 19

Description

Out of bounds write in ANGLE in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5google/chrome139.0.7258.127139.0.7258.127
NVDgoogle/chrome< 139.0.7258.127
Debianchromium/chromium< 139.0.7258.127-1~deb12u1+2

🔴Vulnerability Details

3
CVEList
CVE-2025-8901: Out of bounds write in ANGLE in Google Chrome prior to 1392025-08-13
OSV
CVE-2025-8901: Out of bounds write in ANGLE in Google Chrome prior to 1392025-08-13
GHSA
GHSA-9369-5fxh-crgj: Out of bounds write in ANGLE in Google Chrome prior to 1392025-08-13

📋Vendor Advisories

3
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2025-89012025-08-19
Microsoft
Chromium: CVE-2025-8901 Out of bounds write in ANGLE2025-08-12
Debian
CVE-2025-8901: chromium - Out of bounds write in ANGLE in Google Chrome prior to 139.0.7258.127 allowed a ...2025
CVE-2025-8901 — Out-of-bounds Write in Google Chrome | cvebase