CVE-2025-6558
Google Chromium ANGLE and GPU Improper Input Validation Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 12 August 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 9.59% probability · 95th percentile
- CISA KEV
- Listed 22 July 2025 · due 12 August 2025
- Weakness
- CWE-20
- Affected
- google/chrome · debian/debian linux · apple/safari · apple/ipados · apple/iphone os · apple/macos · apple/visionos · apple/watchos · wpewebkit/wpe webkit · webkitgtk/webkitgtk
- Source
- chrome-cve-admin@google.com
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://chromereleases.googleblog.com/2025/07/stable-channel-update-for-desktop_15.html ; https://nvd.nist.gov/vuln/detail/CVE-2025-6558
References
- https://chromereleases.googleblog.com/2025/07/stable-channel-update-for-desktop_15.htmlRelease Notes
- https://issues.chromium.org/issues/427162086Issue Tracking, Permissions Required
- http://seclists.org/fulldisclosure/2025/Aug/0Third Party Advisory
- http://seclists.org/fulldisclosure/2025/Jul/30Third Party Advisory
- http://seclists.org/fulldisclosure/2025/Jul/32Third Party Advisory
- http://seclists.org/fulldisclosure/2025/Jul/35Third Party Advisory
- http://seclists.org/fulldisclosure/2025/Jul/37Third Party Advisory
- http://www.openwall.com/lists/oss-security/2025/08/02/1Mailing List
- https://lists.debian.org/debian-lts-announce/2025/08/msg00015.htmlMailing List, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-6558US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.