CVE-2025-6558

high

Description

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

References

https://thehackernews.com/2025/08/apple-patches-cve-2025-43300-zero-day.html

https://www.securityweek.com/apple-patches-safari-vulnerability-flagged-as-exploited-against-chrome/

https://www.bleepingcomputer.com/news/security/apple-patches-security-flaw-exploited-in-chrome-zero-day-attacks/

https://thehackernews.com/2025/07/apple-patches-safari-vulnerability-also.html

https://securityaffairs.com/180595/security/apple-fixed-a-zero-day-exploited-in-attacks-against-google-chrome-users.html

https://securityaffairs.com/180293/hacking/u-s-cisa-adds-crushftp-google-chromium-and-sysaid-flaws-to-its-known-exploited-vulnerabilities-catalog.html

https://www.securityweek.com/high-severity-flaws-patched-in-chrome-firefox/

https://www.cisa.gov/news-events/alerts/2025/07/22/cisa-adds-four-known-exploited-vulnerabilities-catalog

https://latesthackingnews.com/2025/07/21/google-patched-a-chrome-zero-day-that-allowed-sandbox-escape/

https://www.malwarebytes.com/blog/news/2025/07/chrome-fixes-6-security-vulnerabilities-get-the-update-now

https://www.helpnetsecurity.com/2025/07/16/update-google-chrome-to-fix-actively-exploited-zero-day-cve-2025-6558/

https://www.bleepingcomputer.com/news/security/google-fixes-actively-exploited-sandbox-escape-zero-day-in-chrome/

https://thehackernews.com/2025/07/urgent-google-releases-critical-chrome.html

https://securityaffairs.com/180001/hacking/cve-2025-6554-marks-the-fifth-actively-exploited-chrome-zero-day-patched-by-google-in-2025.html

https://chromereleases.googleblog.com/2025/07/stable-channel-update-for-desktop_15.html

Details

Source: Mitre, NVD

Published: 2025-07-15

Updated: 2025-07-23

Known Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 8.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00091