ZeroHour

CVE-2025-6558

KEVmass

Actively Exploited Input Validation Flaw in Chrome ANGLE/GPU Allows Sandbox Escape

CISA: Google Chromium ANGLE and GPU Improper Input Validation Vulnerability

CVSS 3.1
8.8 high
EPSS
10%p95
Published
()
KEV added
AI analysis

CVE-2025-6558 is an improper input validation flaw (CWE-20) in the ANGLE graphics translation layer and GPU processing code of Google Chrome/Chromium prior to version 138.0.7204.157. A remote attacker can trigger it by convincing a user to open a crafted HTML page (user interaction is required), and successful exploitation potentially enables a sandbox escape from the browser's renderer with high impact on confidentiality, integrity, and availability. Per the CPE data, exposure extends beyond Chrome to Debian's Chromium package, Apple Safari and its operating systems (iOS, iPadOS, macOS, visionOS, watchOS), and the WebKitGTK and WPE WebKit ports, consistent with the shared ANGLE/WebKit code. Google fixed the issue in Chrome 138.0.7204.157, and CISA added the flaw to the KEV catalog on 2025-07-22, confirming active exploitation in the wild (ransomware use: unknown). EPSS assigns a 9.6% probability of exploitation within 30 days (95th percentile); no public proof-of-concept is known.

What to do: Upgrade Google Chrome/Chromium to 138.0.7204.157 or later immediately, as the flaw is being actively exploited and is KEV-listed. Debian users should install the distribution's patched Chromium package, and operators of Apple platforms, WebKitGTK, or WPE WebKit deployments should apply the corresponding vendor security updates. Federal agencies must apply vendor mitigations per BOD 22-01 within the required timeframe or discontinue use if mitigations are unavailable.

Affected
Google Chromeprior to 138.0.7204.157
Google Chromiumprior to 138.0.7204.157
Debian Linux (Chromium package)
Apple Safari
Apple iOS
Apple iPadOS
Apple macOS
Apple visionOS
Apple watchOS
WPE WebKit
WebKitGTK
Estimated exposure
massbillions of users/installations (Chrome and Chromium-derived browsers) — Chrome holds a dominant share of global browser usage (roughly two-thirds) and Chromium underpins many derivatives, so the plausibly exposed population is on the order of billions of users, though exploitation requires a sandbox-escape…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CISA Known Exploited Vulnerability
Affected
Google Chromium
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
googledebianapplewpewebkitwebkitgtk
Products
chrome, debian linux, safari, ipados, iphone os, macos, visionos, watchos, wpe webkit, webkitgtk
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news