Bug 2388151 (CVE-2025-8901)

Summary: CVE-2025-8901 chromium-browser: ANGLE Out-of-Bounds Write Vulnerability
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in chromium-browser. An out-of-bounds write vulnerability exists within the ANGLE graphics component, allowing a remote attacker to trigger out-of-bounds memory access by providing a specially crafted HTML page. This allows an attacker to potentially manipulate memory contents. The vulnerability is triggered by processing malicious graphics instructions. This can lead to unexpected program behavior.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2388157, 2388158    
Bug Blocks:    

Description OSIDB Bzimport 2025-08-13 04:01:20 UTC
Out of bounds write in ANGLE in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)