← Back

CVE-2025-6558

nvd nist
Published: Jul 15, 2025Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Affected (10)

Show all products
1 product
Chrome
1 product
Debian Linux
6 products
Ipados
Iphone Os
Macos
Safari
Visionos
Watchos
1 product
Wpe Webkit
1 product
Webkitgtk
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 138.0.7204.157
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.0
Configuration C
6 vulnerable
Vulnerable SoftwareAffected Versions
Before 18.6
Before 18.6
Before 15.6
Before 18.6
Before 2.6
Before 11.6
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2.48.0
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2.48.0

References (10)

Source: chrome-cve-admin@google.com
Issue TrackingPermissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.