Re: WebKitGTK and WPE WebKit Security Advisory WSA-2026-0006
An oss-security reply points to WebKit advisory coverage of CVE-2025-6558.
An oss-security reply references the WebKitGTK and WPE WebKit security advisory thread WSA-2026-0006. The message consists of a link to the WebKitGTK advisory page anchored at CVE-2025-6558. It provides no description of the flaw, affected versions, patches, or exploitation status.
- oss-security reply references WebKitGTK and WPE WebKit advisory WSA-2026-0006.
- The message links the advisory page anchor for CVE-2025-6558.
- No impact, patch, or exploitation details are included in the post.
Vulnerabilities mentionedAll →
- CVE-2025-65588.810%Actively Exploited Input Validation Flaw in Chrome ANGLE/GPU Allows Sandbox Escapepublished · Google Chrome KEV
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-6558 | Actively Exploited Input Validation Flaw in Chrome ANGLE/GPU Allows Sandbox Escape CVE-2025-6558 is an improper input validation flaw (CWE-20) in the ANGLE graphics translation layer and GPU processing code of Google Chrome/Chromium prior to version 138.0.7204.157. A remote attacker can trigger it by convincing a user to open a crafted HTML page (user interaction is required), and successful exploitation potentially enables a sandbox escape from the browser's renderer with high impact on confidentiality, integrity, and availability. Per the CPE data, exposure extends beyond Chrome to Debian's Chromium package, Apple Safari and its operating systems (iOS, iPadOS, macOS, visionOS, watchOS), and the WebKitGTK and WPE WebKit ports, consistent with the shared ANGLE/WebKit code. Google fixed the issue in Chrome 138.0.7204.157, and CISA added the flaw to the KEV catalog on 2025-07-22, confirming active exploitation in the wild (ransomware use: unknown). EPSS assigns a 9.6% probability of exploitation within 30 days (95th percentile); no public proof-of-concept is known. |
Posted by Adrian Perez de Castro on Sep 30 Hello all, https://webkitgtk.org/security/WSA-2025-0005.html#CVE-2025-6558
This source does not provide full text. Read it at seclists.org.