WebKitGTK and WPE WebKit Security Advisory WSA-2026-0006 linked to CVE-2025-6558
WebKitGTK and WPE WebKit advisory WSA-2026-0006 was announced on oss-security; a follow-up reply ties it to CVE-2025-6558.
On Sep 28, Adrian Perez de Castro posted WebKitGTK and WPE WebKit Security Advisory WSA-2026-0006 to the oss-security list, pointing to the advisory on webkitgtk.org; the excerpt listed no CVE identifiers, affected versions, or exploitation status. On Sep 30, an oss-security reply in the same thread linked the advisory page anchored at CVE-2025-6558, associating that CVE with WSA-2026-0006, though the reply itself contained no description of the flaw, affected versions, patches, or exploitation status. As a result, the advisory's only publicly identified issue so far is CVE-2025-6558, with impact and remediation details still not stated in the posts.
- WebKitGTK and WPE WebKit published security advisory WSA-2026-0006.
- Announced to the oss-security list on Sep 28 by Adrian Perez de Castro, pointing to webkitgtk.org.
- A Sep 30 oss-security reply links the advisory page anchor for CVE-2025-6558.
- Neither post states affected versions, patch details, or whether any issue is being exploited.
- No conflicting facts between the two reports; the second adds a CVE reference absent from the first.
Coverage timelineoldest first · each row is one article
- · 4d agoWebKitGTK and WPE WebKit Security Advisory WSA-2026-0006
oss-security· 34
WebKitGTK and WPE WebKit published security advisory WSA-2026-0006.
- · 2d agoRe: WebKitGTK and WPE WebKit Security Advisory WSA-2026-0006
oss-security· 24
An oss-security reply points to WebKit advisory coverage of CVE-2025-6558.
Vulnerabilities in this storyAll →
- CVE-2025-65588.810%Actively Exploited Input Validation Flaw in Chrome ANGLE/GPU Allows Sandbox Escapepublished · Google Chrome KEV
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-6558 | Actively Exploited Input Validation Flaw in Chrome ANGLE/GPU Allows Sandbox Escape CVE-2025-6558 is an improper input validation flaw (CWE-20) in the ANGLE graphics translation layer and GPU processing code of Google Chrome/Chromium prior to version 138.0.7204.157. A remote attacker can trigger it by convincing a user to open a crafted HTML page (user interaction is required), and successful exploitation potentially enables a sandbox escape from the browser's renderer with high impact on confidentiality, integrity, and availability. Per the CPE data, exposure extends beyond Chrome to Debian's Chromium package, Apple Safari and its operating systems (iOS, iPadOS, macOS, visionOS, watchOS), and the WebKitGTK and WPE WebKit ports, consistent with the shared ANGLE/WebKit code. Google fixed the issue in Chrome 138.0.7204.157, and CISA added the flaw to the KEV catalog on 2025-07-22, confirming active exploitation in the wild (ransomware use: unknown). EPSS assigns a 9.6% probability of exploitation within 30 days (95th percentile); no public proof-of-concept is known. |