8.8

CVE-2025-6558

Warnung
Medienbericht
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Google ≫ Chrome Version < 138.0.7204.157
Debian ≫ Debian Linux Version 11.0
Apple ≫ Safari Version < 18.6
Apple ≫ iPadOS Version < 18.6
Apple ≫ iPhone OS Version < 18.6
Apple ≫ macOS Version < 15.6
Apple ≫ visionOS Version < 2.6
Apple ≫ watchOS Version < 11.6
Wpewebkit ≫ Wpe Webkit Version < 2.48.5
Webkitgtk ≫ Webkitgtk Version < 2.48.5
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login

22.07.2025: CISA Known Exploited Vulnerabilities (KEV) Catalog

Google Chromium ANGLE and GPU Improper Input Validation Vulnerability

Schwachstelle

Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Beschreibung

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 9.26% 0.949
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
09.08.2025 11:36
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
09.08.2025 11:36
https://chromereleases.googleblog.com/2025/07/stable-channel-update-for-desktop_15.html
Release Notes
https://issues.chromium.org/issues/427162086
Issue Tracking
Permissions Required
https://lists.debian.org/debian-lts-announce/2025/08/msg00015.html
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2025/08/02/1
Mailing List
http://seclists.org/fulldisclosure/2025/Aug/0
Third Party Advisory
http://seclists.org/fulldisclosure/2025/Jul/30
Third Party Advisory
http://seclists.org/fulldisclosure/2025/Jul/32
Third Party Advisory
http://seclists.org/fulldisclosure/2025/Jul/35
Third Party Advisory
http://seclists.org/fulldisclosure/2025/Jul/37
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-6558
US Government Resource
http://www.openwall.com/lists/oss-security/2026/09/30/18
Mailing List