Apple Patches Safari Vulnerability Also Exploited as Zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-6558 | Actively Exploited Input Validation Flaw in Chrome ANGLE/GPU Allows Sandbox Escape CVE-2025-6558 is an improper input validation flaw (CWE-20) in the ANGLE graphics translation layer and GPU processing code of Google Chrome/Chromium prior to version 138.0.7204.157. A remote attacker can trigger it by convincing a user to open a crafted HTML page (user interaction is required), and successful exploitation potentially enables a sandbox escape from the browser's renderer with high impact on confidentiality, integrity, and availability. Per the CPE data, exposure extends beyond Chrome to Debian's Chromium package, Apple Safari and its operating systems (iOS, iPadOS, macOS, visionOS, watchOS), and the WebKitGTK and WPE WebKit ports, consistent with the shared ANGLE/WebKit code. Google fixed the issue in Chrome 138.0.7204.157, and CISA added the flaw to the KEV catalog on 2025-07-22, confirming active exploitation in the wild (ransomware use: unknown). EPSS assigns a 9.6% probability of exploitation within 30 days (95th percentile); no public proof-of-concept is known. Do: Upgrade Google Chrome/Chromium to 138.0.7204.157 or later immediately, as the flaw is being actively exploited and is KEV-listed. Debian users should install the distribution's patched Chromium package, and operators of Apple platforms, WebKitGTK, or WPE WebKit deployments should apply the corresponding vendor security updates. Federal agencies must apply vendor mitigations per BOD 22-01 within the required timeframe or discontinue use if mitigations are unavailable. | 8.8 | 10% | KEV |
| massbillions of users/installations (Chrome and Chromium-derived browsers) |
Full article349 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJul 30, 2025Vulnerability / Zero-Day
Apple on Tuesday released security updates for its entire software portfolio, including a fix for a vulnerability that Google said was exploited as a zero-day in the Chrome web browser earlier this month.
The vulnerability, tracked as CVE-2025-6558 (CVSS score: 8.8), is an incorrect validation of untrusted input in the browser's ANGLE and GPU components that could result in a sandbox escape via a crafted HTML page.
While there are no details on how the issue has been weaponized by threat actors, Google acknowledged that an "exploit for CVE-2025-6558 exists in the wild." Clément Lecigne and Vlad Stolyarov of Google's Threat Analysis Group (TAG) have been credited with discovering and reporting the shortcoming.
The iPhone maker, in its latest round of software updates, also included patches for CVE-2025-6558, stating the vulnerability impacts the WebKit browser engine that powers its Safari browser.
"This is a vulnerability in open-source code and Apple Software is among the affected projects," the company said in an advisory, adding it could be exploited to result in an unexpected crash of Safari when processing maliciously crafted web content.
The bug has been addressed in the following versions -
- iOS 18.6 and iPadOS 18.6 - iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later
- iPadOS 17.7.9 - iPad Pro 12.9-inch 2nd generation, iPad Pro 10.5-inch, and iPad 6th generation
- macOS Sequoia 15.6 - Macs running macOS Sequoia
- tvOS 18.6 - Apple TV HD and Apple TV 4K (all models)
- watchOS 11.6 - Apple Watch Series 6 and later
- visionOS 2.6 - Apple Vision Pro
While there is no evidence that the vulnerability has been used to target Apple device users, it's always a good practice to update to the latest versions of the software for optimal protection.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/07/apple-patches-safari-vulnerability-also.html