Vulnerability record · CVE-2025-6558 · published 15 July 2025
CVE-2025-6558: Chrome ANGLE and GPU input validation flaw enables sandbox escape
Google · Chrome
Google Chrome before 138.0.7204.157 fails to properly validate untrusted input in ANGLE and the GPU component, allowing a crafted HTML page to trigger a sandbox escape. The flaw is rated high severity by Chromium and carries a CVSS 3.1 base score of 8.8, and it affects not only Chrome but also WebKit-based products (Safari, iOS/iPadOS/macOS/watchOS/visionOS, WPE WebKit, WebKitGTK) per the vendor list.
Description
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows a sandbox escape with a CVSS of 8.8 and is listed in CISA KEV as exploited in the wild, though it requires user interaction to trigger.
What it is
Google Chrome before 138.0.7204.157 fails to properly validate untrusted input in ANGLE and the GPU component, allowing a crafted HTML page to trigger a sandbox escape. The flaw is rated high severity by Chromium and carries a CVSS 3.1 base score of 8.8, and it affects not only Chrome but also WebKit-based products (Safari, iOS/iPadOS/macOS/watchOS/visionOS, WPE WebKit, WebKitGTK) per the vendor list.
Impact
An attacker who gets a victim to load a crafted HTML page can escape the browser sandbox, which typically means code execution at the level of the browser process and access to data and resources outside the sandbox.
Attack surface
Reached over the network through a crafted HTML page rendered by the browser; no privileges are required, but user interaction (opening the page) is needed per the CVSS vector AV:N/AC:L/PR:N/UI:R.
Exploitation
CVE-2025-6558 was added to CISA KEV on 2025-07-22 with a remediation due date of 2025-08-12, indicating known exploitation in the wild; EPSS shows a 30-day probability of about 9.6 percent (95th percentile). No ransomware campaign use is documented.
What to do
- Update Chrome to 138.0.7204.157 or later, and apply the corresponding WebKit/WebKitGTK/WPE WebKit and Apple OS updates from the affected vendors.
- Follow CISA KEV required action: apply vendor mitigations, apply BOD 22-01 guidance for cloud services, or discontinue use of the product if no mitigation is available.
- Enforce automatic browser updates and verify version compliance across managed endpoints.
- Reduce exposure by restricting browsing to trusted sites and isolating high-risk browsing in a separate, hardened environment until patching is complete.
Detection
- Monitor for Chrome/WebKit processes spawning unexpected child processes or making anomalous outbound connections after page loads.
- Hunt for crashes or abnormal GPU/ANGLE process behavior correlated with visits to untrusted or newly registered domains.
- Track endpoint browser version inventory to find hosts still below 138.0.7204.157 or unpatched WebKit builds.
- Review proxy and DNS logs for delivery of exploit pages to browsers in the affected versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-6558 to the Known Exploited Vulnerabilities catalog on 22 July 2025 as "Google Chromium ANGLE and GPU Improper Input Validation Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 12 August 2025.
Affected products
10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://chromereleases.googleblog.com/2025/07/stable-channel-update-for-desktop_15.html | Release Notes |
| https://issues.chromium.org/issues/427162086 | Issue TrackingPermissions Required |
| http://seclists.org/fulldisclosure/2025/Aug/0 | Third Party Advisory |
| http://seclists.org/fulldisclosure/2025/Jul/30 | Third Party Advisory |
| http://seclists.org/fulldisclosure/2025/Jul/32 | Third Party Advisory |
| http://seclists.org/fulldisclosure/2025/Jul/35 | Third Party Advisory |
| http://seclists.org/fulldisclosure/2025/Jul/37 | Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2025/08/02/1 | Mailing List |
| https://lists.debian.org/debian-lts-announce/2025/08/msg00015.html | Mailing ListThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-6558 | US Government Resource |
Track CVE-2025-6558 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-6558), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.