CVE-2025-6558
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- Affected products
- Alt Linux, Almalinux, Astra Linux, Centos, Debian, Google Chrome, Linuxmint, Apple Macos
- Google Chrome
- < 138.0.7204.157
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 9.6% (95th percentile)
- Weakness
- CWE-20
- NVD status
- Analyzed
- Published
- 2025-07-15
CVE-2025-6558 at NVD
8 known exploits for CVE-2025-6558
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2025-6558-Proof-Of-Concept
CVE-2025-6558-exp
π Apple Security Advisory 07-29-2025-6
π Apple Security Advisory 07-29-2025-7
π Apple Security Advisory 07-29-2025-8
π Apple Security Advisory 07-29-2025-1
π Apple Security Advisory 07-29-2025-2
π Apple Security Advisory 07-29-2025-3