{"id":6102,"date":"2025-08-13T10:03:34","date_gmt":"2025-08-13T10:03:34","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/13\/multiple-chrome-high-severity-vulnerabilities-let-attackers-execute-arbitrary-code\/"},"modified":"2025-08-13T10:03:34","modified_gmt":"2025-08-13T10:03:34","slug":"multiple-chrome-high-severity-vulnerabilities-let-attackers-execute-arbitrary-code","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/13\/multiple-chrome-high-severity-vulnerabilities-let-attackers-execute-arbitrary-code\/","title":{"rendered":"Multiple Chrome High-Severity Vulnerabilities Let Attackers Execute Arbitrary Code"},"content":{"rendered":"<p>    Multiple Chrome High-Severity Vulnerabilities Let Attackers Execute Arbitrary Code<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Google Chrome has released a critical security update addressing six vulnerabilities that could potentially enable arbitrary code execution on affected systems.\u00a0<\/p>\n<p>The stable channel update to version 139.0.7258.127\/.128 for Windows and Mac, and 139.0.7258.127 for Linux, contains patches for multiple high-severity security flaws that pose significant risks to user data and system integrity.<\/p>\n<pre class=\"wp-block-preformatted\"><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-vivid-cyan-blue-color\">Key Takeaways<\/mark><\/strong><br>1. Chrome fixes six vulnerabilities, including three that enable code execution.<br>2. Affects V8 engine and graphics - allows malicious code execution.<br>3. Update Chrome now via Settings &gt; About Chrome.<\/pre>\n<h2 class=\"wp-block-heading\" id=\"h-high-severity-vulnerabilities-addressed\"><strong>High-Severity Vulnerabilities Addressed<\/strong><\/h2>\n<p>The security update targets three high-severity <a href=\"https:\/\/cybersecuritynews.com\/cisa-releases-10-ics-advisories\/\" target=\"_blank\" rel=\"noreferrer noopener\">vulnerabilities<\/a> that could lead to arbitrary code execution.\u00a0<\/p>\n<p>CVE-2025-8879 represents a heap <a href=\"https:\/\/cybersecuritynews.com\/tag\/what-is-buffer-overflow\/\" target=\"_blank\" rel=\"noreferrer noopener\">buffer overflow vulnerability<\/a> in the libaom library, which handles video encoding and decoding operations.\u00a0<\/p>\n<p>This type of vulnerability allows attackers to write data beyond allocated memory boundaries, potentially overwriting critical system information.<\/p>\n<p>CVE-2025-8880 addresses a race condition in Google\u2019s V8 JavaScript engine, reported by security researcher Seunghyun Lee.\u00a0<\/p>\n<p>Race conditions occur when multiple processes attempt to access shared resources simultaneously, creating unpredictable behavior that attackers can exploit.\u00a0<\/p>\n<p>The third high-severity flaw, CVE-2025-8901, involves an out-of-bounds write vulnerability in ANGLE (Almost Native Graphics Layer Engine), which translates OpenGL ES API calls to hardware-supported APIs.<\/p>\n<p>Chrome\u2019s security team utilized multiple advanced detection methodologies to identify these vulnerabilities, including AddressSanitizer for detecting memory corruption bugs, MemorySanitizer for uninitialized memory reads, and UndefinedBehaviorSanitizer for catching undefined behavior in C\/C++ code.\u00a0<\/p>\n<p>The update also incorporates Control Flow Integrity mechanisms and findings from libFuzzer and AFL (American Fuzzy Lop) testing frameworks.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-medium-severity-vulnerabilities-addressed\"><strong>Medium- Severity Vulnerabilities Addressed<\/strong><\/h2>\n<p>Additional medium-severity vulnerabilities were also patched, including CVE-2025-8881, which addresses inappropriate implementation in the File Picker component, and CVE-2025-8882, a use-after-free vulnerability in the Aura windowing system.\u00a0<\/p>\n<p>Use-after-free vulnerabilities occur when programs continue to use memory after it has been freed, leading to potential code execution opportunities.<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<td><strong>CVE ID<\/strong><\/td>\n<td><strong>Title<\/strong><\/td>\n<td><strong>Severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-8879<\/td>\n<td>Heap buffer overflow in libaom<\/td>\n<td>High<\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-8880<\/td>\n<td>Race in V8<\/td>\n<td>High<\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-8901<\/td>\n<td>Out of bounds write in ANGLE<\/td>\n<td>High<\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-8881<\/td>\n<td>Inappropriate implementation in File Picker<\/td>\n<td>Medium<\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-8882<\/td>\n<td>Use after free in Aura<\/td>\n<td>Medium<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2 class=\"wp-block-heading\" id=\"h-mitigations\"><strong>Mitigations<\/strong><\/h2>\n<p>These vulnerabilities collectively present serious security risks, as heap buffer overflows and race conditions in core browser components can be exploited to execute malicious code with browser privileges.\u00a0<\/p>\n<p>The <a href=\"https:\/\/chromereleases.googleblog.com\/2025\/08\/stable-channel-update-for-desktop_12.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">automatic rollout<\/a> will occur over the coming days and weeks, but users should manually update Chrome through Settings &gt; About Chrome.<\/p>\n<p>System administrators should prioritize this update deployment, particularly in enterprise environments where browsers process sensitive data.\u00a0<\/p>\n<p>The Chrome team\u2019s collaboration with external security researchers, including anonymous contributors and Google\u2019s Big Sleep project, demonstrates the ongoing effort to identify and remediate security vulnerabilities before they reach stable release channels.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong><code>Boost\u00a0your\u00a0SOC and help your team protect your business with free top-notch threat intelligence:\u00a0<a href=\"https:\/\/intelligence.any.run\/plans\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=alert_fatigue&amp;utm_content=lookup_plan&amp;utm_term=120825\">Request TI Lookup Premium Trial<\/a>.<\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/chrome-security-update-aug\/\">Multiple Chrome High-Severity Vulnerabilities Let Attackers Execute Arbitrary Code<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Florence Nightingale<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/chrome-security-update-aug\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Multiple Chrome High-Severity Vulnerabilities Let Attackers Execute Arbitrary Code Google Chrome has released a critical security update addressing six vulnerabilities that could potentially enable arbitrary code execution on affected systems.\u00a0 The stable channel update to version 139.0.7258.127\/.128 for Windows and Mac, and 139.0.7258.127 for Linux, contains patches for multiple high-severity security flaws that pose significant [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-6102","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6102"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6102"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6102\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6102"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6102"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6102"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}