⚠ Actively exploited
Added to CISA KEV on 2025-07-22. Federal agencies required to patch by 2025-08-12. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable..

CVE-2025-6558

Severity
8.8HIGH
EPSS
0.2%
top 62.04%
CISA KEV
KEV
Added 2025-07-22
Due 2025-08-12
Exploit
No known exploits
Timeline
PublishedJul 15
KEV addedJul 22
KEV dueAug 12
Latest updateAug 19
CISA Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Description

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages13 packages

CVEListV5google/chrome138.0.7204.157138.0.7204.157
NVDgoogle/chrome< 138.0.7204.157
Debianchromium< 138.0.7204.157-1~deb12u1+2
NVDapple/macos< 15.6
NVDapple/ipados< 18.6

Also affects: Debian Linux 11.0

🔴Vulnerability Details

4
OSV
CVE-2025-6558: Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 1382025-07-15
CVEList
CVE-2025-6558: Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 1382025-07-15
GHSA
GHSA-5w32-633g-38jh: Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 1382025-07-15
VulnCheck
Google Chromium ANGLE and GPU Improper Input Validation Vulnerability2025

📋Vendor Advisories

13
Ubuntu
WebKitGTK vulnerabilities2025-08-19
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2025-65582025-07-30
Apple
CVE-2025-6558: Safari 18.62025-07-30
Apple
CVE-2025-6558: iPadOS 17.7.92025-07-29
Apple
CVE-2025-6558: watchOS 11.62025-07-29

🕵️Threat Intelligence

1
Bleepingcomputer
Apple patches security flaw exploited in Chrome zero-day attacks2025-07-30