Chrome updates 139.0.7258.154/155 for Windows and macOS, and 139.0.7258.154 for Linux available
With another Chrome update, Google is closing a critical security vulnerability in its browser that was once again uncovered by its own AI.
Google has fixed a vulnerability in the new Chrome versions 139.0.7258.154/155 for Windows and macOS, and 139.0.7258.154 for Linux. According to Google, the vulnerability has not yet been exploited for attacks. The makers of other Chromium-based browsers are expected to follow suit in the coming days.
The Chrome Release Blog presents the fixed vulnerability, which, as in the previous week, is being treated as a vulnerability discovered by external security researchers. However, Google Big Sleep is again listed as the discoverer of the vulnerability CVE-2025-9478. This is a Gemini-based "AI" tool for detecting security vulnerabilities. It is designed to detect vulnerabilities independently, without human assistance.
Since the security findings of such "AI" tools should always be treated with caution, they are reviewed by experts. However, Google does not provide any information on how many misdiagnoses Big Sleep makes per hit. In this case, however, Big Sleep apparently wasn't wrong – Google even classifies the vulnerability CVE-2025-9478 as critical. It is a use-after-free vulnerability in the Angle graphics library. Whether such "AI" tools will be necessary in the near future to find security vulnerabilities in AI-generated code remains to be seen.
Chrome usually updates automatically when a new version is available. You can manually initiate the update check using the menu item "Help" "About Google Chrome." Google has also released Chrome for Android 139.0.7258.158. The Android version fixes the same vulnerabilities as the desktop version.