CVE-2025-6558
Google Chrome
Published 15 Jul 2025 · updated 1 Oct 2026 · Analyzed
8.8 High · CVSS 3.1, CISA ADP
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 22 Jul 2025, with a remediation deadline of 12 Aug 2025 for US federal agencies.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Description
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
References
- chromereleases.googleblog.com/2025/07/stable-channel-update-for-desktop_15.html · Release Notes
- issues.chromium.org/issues/427162086 · Issue Tracking, Permissions Required
- seclists.org/fulldisclosure/2025/Aug/0 · Third Party Advisory
- seclists.org/fulldisclosure/2025/Jul/30 · Third Party Advisory
- seclists.org/fulldisclosure/2025/Jul/32 · Third Party Advisory
- seclists.org/fulldisclosure/2025/Jul/35 · Third Party Advisory
- seclists.org/fulldisclosure/2025/Jul/37 · Third Party Advisory
- www.openwall.com/lists/oss-security/2025/08/02/1 · Mailing List
- www.openwall.com/lists/oss-security/2026/09/30/18 · Mailing List
- lists.debian.org/debian-lts-announce/2025/08/msg00015.html · Mailing List, Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-6558 · US Government Resource