Google fixed Chrome flaw found by Big Sleep AI
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-9132 | Out of bounds write in V8 in Google Chrome prior to 139.0.7258.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Out of bounds write in V8 in Google Chrome prior to 139.0.7258.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) NVD description · AI analysis pending | 8.8 | 3% |
| — |
Full article137 words · extracted from securityaffairs.com · click to collapse

Google Chrome 139 addressed a high-severity V8 flaw, tracked as CVE-2025-9132, found by Big Sleep AI
Google Chrome 139 addressed a high-severity vulnerability, tracked as CVE-2025-9132, in its open source high-performance JavaScript and WebAssembly engine V8.
The vulnerability is an out-of-bounds write issue in the V8 JavaScript engine that was discovered by Big Sleep AI.
Big Sleep is an AI agent developed by Google DeepMind and Project Zero to automate the discovery of real-world software vulnerabilities.
Chrome 139 updates (Windows/macOS: 139.0.7258.138/.139, Linux: 139.0.7258.138) patch the V8 flaw CVE-2025-9132, rolling out to all users soon.
Google did not say if the vulnerability is being exploited in attacks in the wild, however, users are urged to update their software as soon as possible.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Chrome)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/181338/security/google-fixed-chrome-flaw-found-by-big-sleep-ai.html