Google has fixed a critical vulnerability in Chrome versions 139.0.7258.154/155 for Windows and macOS and 139.0.7258.154 for Linux. According to Google, the vulnerability has not yet been exploited for attacks in the wild. The manufacturers of other Chromium-based browsers are expected to follow suit in the coming days.
In the Chrome Releases blog post , Krishna Govind presents the eliminated vulnerability ( CVE-2025-9478 ), which is treated as if it were discovered by external security researchers, but Google Big Sleep is named as the discoverer of the vulnerability. This is an “AI” tool based on Gemini for detecting security vulnerabilities and it’s designed to detect vulnerabilities on its own without human assistance.
As the security findings of such “AI” tools should always be t