chromium-browser: angle: ANGLE Out-of-Bounds Write Vulnerability
Published Aug 13, 2025
8.8
HIGHCVSS 3.1
EPSS 0.33%
Description
Out of bounds write in ANGLE in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Affected products
-
- Version 139.0.7258.127StatusaffectedConstraints<139.0.7258.127
- Version
No data.
Red Hat Enterprise Linux 6
webkitgtk
Out of support scope
Red Hat Enterprise Linux 7
webkitgtk3
Affected
Red Hat Enterprise Linux 7
webkitgtk4
Affected
Red Hat Enterprise Linux 8
webkit2gtk3
Affected
Red Hat Enterprise Linux 9
webkit2gtk3
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | webkitgtk | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | webkitgtk3 | Affected | n/a |
| Red Hat Enterprise Linux 7 | webkitgtk4 | Affected | n/a |
| Red Hat Enterprise Linux 8 | webkit2gtk3 | Affected | n/a |
| Red Hat Enterprise Linux 9 | webkit2gtk3 | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (6)
- https://access.redhat.com/security/cve/CVE-2025-8901 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2388151 Issue Tracking
- https://chromereleases.googleblog.com/2025/08/stable-channel-update-for-desktop_12.html Release NotesVendor Advisory
- https://issues.chromium.org/issues/435139154 Issue TrackingPermissions Required
- https://nvd.nist.gov/vuln/detail/CVE-2025-8901
- https://www.cve.org/CVERecord?id=CVE-2025-8901
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2025-8901 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2388151 | Issue Tracking | |
| https://chromereleases.googleblog.com/2025/08/stable-channel-update-for-desktop_12.html | Release NotesVendor Advisory | |
| https://issues.chromium.org/issues/435139154 | Issue TrackingPermissions Required | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-8901 | ||
| https://www.cve.org/CVERecord?id=CVE-2025-8901 |
Change history (0)
No recorded changes yet.