← Vulnerability feed

Vulnerability record · CVE-2025-6558 · published 15 July 2025

CVE-2025-6558: Chrome ANGLE and GPU input validation flaw enables sandbox escape

Google · Chrome

Google Chrome before 138.0.7204.157 fails to properly validate untrusted input in ANGLE and the GPU component, allowing a crafted HTML page to trigger a sandbox escape. The flaw is rated high severity by Chromium and carries a CVSS 3.1 base score of 8.8, and it affects not only Chrome but also WebKit-based products (Safari, iOS/iPadOS/macOS/watchOS/visionOS, WPE WebKit, WebKitGTK) per the vendor list.

8.8 CVSS 3.1 High CISA KEV since 22 Jul 2025 EPSS 9.6% · top 4.7% CWE-20 · Improper input validation
8.8CVSS 3.1 base score
9.6%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
10Affected product versions listed by NVD
10References
24 Sep 2026Last modified by NVD

Description

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw allows a sandbox escape with a CVSS of 8.8 and is listed in CISA KEV as exploited in the wild, though it requires user interaction to trigger.

What it is

Google Chrome before 138.0.7204.157 fails to properly validate untrusted input in ANGLE and the GPU component, allowing a crafted HTML page to trigger a sandbox escape. The flaw is rated high severity by Chromium and carries a CVSS 3.1 base score of 8.8, and it affects not only Chrome but also WebKit-based products (Safari, iOS/iPadOS/macOS/watchOS/visionOS, WPE WebKit, WebKitGTK) per the vendor list.

Impact

An attacker who gets a victim to load a crafted HTML page can escape the browser sandbox, which typically means code execution at the level of the browser process and access to data and resources outside the sandbox.

Attack surface

Reached over the network through a crafted HTML page rendered by the browser; no privileges are required, but user interaction (opening the page) is needed per the CVSS vector AV:N/AC:L/PR:N/UI:R.

Exploitation

CVE-2025-6558 was added to CISA KEV on 2025-07-22 with a remediation due date of 2025-08-12, indicating known exploitation in the wild; EPSS shows a 30-day probability of about 9.6 percent (95th percentile). No ransomware campaign use is documented.

What to do

  • Update Chrome to 138.0.7204.157 or later, and apply the corresponding WebKit/WebKitGTK/WPE WebKit and Apple OS updates from the affected vendors.
  • Follow CISA KEV required action: apply vendor mitigations, apply BOD 22-01 guidance for cloud services, or discontinue use of the product if no mitigation is available.
  • Enforce automatic browser updates and verify version compliance across managed endpoints.
  • Reduce exposure by restricting browsing to trusted sites and isolating high-risk browsing in a separate, hardened environment until patching is complete.

Detection

  • Monitor for Chrome/WebKit processes spawning unexpected child processes or making anomalous outbound connections after page loads.
  • Hunt for crashes or abnormal GPU/ANGLE process behavior correlated with visits to untrusted or newly registered domains.
  • Track endpoint browser version inventory to find hosts still below 138.0.7204.157 or unpatched WebKit builds.
  • Review proxy and DNS logs for delivery of exploit pages to browsers in the affected versions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-6558 to the Known Exploited Vulnerabilities catalog on 22 July 2025 as "Google Chromium ANGLE and GPU Improper Input Validation Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 12 August 2025.

Affected products

10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-6558 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-43300Apple iOS, iPadOS and macOS out-of-bounds write via malicious imageAn out-of-bounds write in Apple iOS, iPadOS and macOS is triggered when processing a malicious image file, causing memory corruption. Apple states th…KEVEPSS 32%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2025-24085Apple iOS, iPadOS, macOS, tvOS, visionOS, watchOS Use-After-Free Privilege EscalationA use-after-free flaw in Apple's operating systems was fixed through improved memory management in iOS 18.3, iPadOS 18.3 and 17.7.6, macOS Sequoia 15…KEVEPSS 18%analysed9.8CVE-2026-65400Apple macOS Screen Sharing authentication bypassAn improper authentication flaw in Apple macOS Screen Sharing allows a network attacker to authenticate without valid credentials. Apple fixed it via…KEVEPSS 1.2%analysed9.8CVE-2025-31200Apple OS media parsing memory corruption allows code executionA memory corruption flaw in Apple's audio stream processing was fixed with improved bounds checking across iOS, iPadOS, macOS, tvOS, visionOS and wat…KEVEPSS 19%analysed9.8CVE-2025-31201Apple OS Pointer Authentication bypass via arbitrary read/writeApple removed vulnerable code that allowed an attacker holding arbitrary read and write capability to bypass Pointer Authentication across iOS, iPadO…KEVEPSS 14%analysed9.8CVE-2022-22587Apple iOS, iPadOS and macOS kernel memory corruption via out-of-bounds writeAn out-of-bounds write (CWE-787) in Apple iOS, iPadOS and macOS is caused by insufficient input validation and can corrupt memory. Apple states it is…KEVEPSS 12%analysed9.8CVE-2021-1870Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions, affecting macOS Big Sur, Catalina, Mojave, iOS and iPadOS, plus WebKitGTK a…KEVEPSS 7.7%analysed

Source: NIST National Vulnerability Database (record CVE-2025-6558), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.