Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-9478 PoC — Google Chrome 资源管理错误漏洞

Source
Associated Vulnerability
Title:Google Chrome 资源管理错误漏洞 (CVE-2025-9478)
Description:Use after free in ANGLE in Google Chrome prior to 139.0.7258.154 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Description
Remediation of Microsoft Edge (Chromium) Remote Code Execution vulnerability (CVE-2025-9478, Plugin ID: 258091). Documentation includes before/after evidence, remediation steps, and Tenable validation.
Readme
# STIG – Microsoft Edge (Chromium) < 139.0.3405.125 Remote Code Execution (CVE-2025-9478, Plugin ID: 258091)

## Before
- **Finding:** Microsoft Edge (version 139.0.3405.86) was outdated and vulnerable to a critical Remote Code Execution (RCE) flaw (CVE-2025-9478).  
- **Risk:** Attackers could exploit a use-after-free in ANGLE to execute arbitrary code through crafted HTML pages.  
- **Evidence:**  
  ![Before – Tenable Finding](Edge-Before-Finding.png)  
  ![Before – Version Details](Edge-Before-Details.png)  

---

## Remediation
1. Updated Microsoft Edge to version `139.0.3405.125` (patched).  
2. Verified the version update (`edge://settings/help`).  
3. Restarted Edge to finalize the patch.  
4. Performed a Tenable rescan to confirm the vulnerability was resolved.  

---

## After
Microsoft Edge successfully updated to version `139.0.3405.125`, mitigating CVE-2025-9478 and preventing potential remote code execution.  

**Evidence:**  
Edge-After-Details.png  
Edge-After-Tenable-Rescan.png

File Snapshot

[4.0K] /data/pocs/5543214bd71ffefbbd04917dbdf5e85058bc1ff4 ├── [159K] Edge-Before-Details.png ├── [108K] Edge-Before-Finding.png └── [1017] README.md 0 directories, 3 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →