CVE-2025-6558 is a high-severity vulnerability in Google Chrome (prior to version 138.0.7204.157), affecting its ANGLE and GPU components due to insufficient validation of untrusted input. This flaw allows a remote attacker to achieve a sandbox escape by enticing a user to visit a specially crafted HTML page, impacting products from Apple, Debian, Google, WebKitGTK, and WPEWebKit. With a CVSS score of 8.8, it presents a critical risk, as it requires no privileges, has low attack complexity, and can lead to high confidentiality, integrity, and availability impacts. This vulnerability is actively exploited in the wild, as confirmed by its presence in the KEV catalog and numerous media reports, despite no public exploit code being available on platforms like Metasploit or ExploitDB. The significant community discussion and media coverage highlight its widespread concern and the urgency of patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 138.0.7204.157, < 138.0.7204.157CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 138.0.7204.157CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
< 18.6CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
< 18.6CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
HP ThinPro 8.1 SP9 Security Updates
Feb 2, 2026angle: insufficient input validation can cause undefined behavior
Jul 15, 2025Chromium: CVE-2025-6558 Incorrect validation of untrusted input in ANGLE and GPU
Jul 8, 2025