CVE-2025-6558: Google Chromium ANGLE and GPU Improper Input Validation Vulnerability
Published Jul 15, 2025
·Updated
Accessibility. A logic issue was addressed with improved checks.
Credit
Sergei Glazunov(Google Project Zero), Ivan Fratric(Google Project Zero), Andreas Jaegersberger & Ro Achterberg(Nosebeard Labs), Martin Bajanik(Fingerprint), Ammar Askar, Jaydev Ahire, Gilad Moav, Yehuda Afek, Anat Bremler-Barr, Amit Klein, Yuhao Hu, Yan Kang, Chenggang Wu, Xiaojie Wei, Syarif Muhammad Sajjad, shandikri(Trend Micro Zero Day Initiative), Google V8 Security Team, Nan Wang@@eternalsakura13, Ziling Chen, HexRabbit@@h3xr4bb1t(DEVCORE Research Team), Ignacio Sanmillan@@ulexec, Clément Lecigne(Google's Threat Analysis Group), Vlad Stolyarov(Google's Threat Analysis Group), Google's Threat Analysis Group, Hossein Lotfi@@hosselot(Trend Micro Zero Day Initiative), Chi Yuan Chang(ZUSO ART), taikosoup, Gary Kwong(Trend Micro Zero Day Initiative), CVE-2025-43226, Christian Kohlschütter, Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), CVE-2025-6965, Wong Wee Xiang, Himanshu Bharti@@Xpl0itme, Brian Carpenter, Mickey Jin@@patch1t, Dawuge(Shuffle Team), Tony Iskow@@Tybbow, Kirin@@Pwnrin, Wojciech Regula(SecuRing), ABC Research s.r.o., Noah Gregory (wts.dev), MRHAX, Aditya Rana, Seo Hyun-gyu@@wh1te4ever(Xiaomi), Dora Orak(Xiaomi), Minghao Lin@@Y1nKoc(Xiaomi), XiLong Zhang@@Resery4(Xiaomi), noir@@ROIS, fmyy (@风沐云烟), 风沐云烟@@binary_fmyy, Minghao Lin@@Y1nKoc, Gergely Kalman@@gergely_kalman, an anonymous researcher, 2ourc3 | Salim Largo, Anonymous(Trend Micro Zero Day Initiative), Willey Lin, Arsenii Kostromin (0x3c3e), Pyrophoria, Dora Orak, Csaba Fitzl@@theevilbit(Kandji), Minghao Lin, Jiaxun Zhu, Zhongquan Li@@Guluisacat, Koh M. Nakagawa@@tsunek0h(Kandji), an anonymous researcher(Loadshine Lab), Hikerell(Loadshine Lab), @@zlluny, Yuebin Sun@@yuebinsun2020, Shang-De Jiang(CyCraft Technology), Kazma Ye(CyCraft Technology), Nikolai Skliarenko(Trend Micro Zero Day Initiative), Keith Yeo@@kyeojy(Team Orca of Sea Security), Martti Hütt, Jonathan Bar Or@@yo_yo_yo_jbo(Microsoft), Ryan Dowd@@_rdowd
Affected Software
21 affected componentsFixes available
Microsoft Edge (Chromium-based)
Microsoft Edge<138.0.3351.95
Google Chromium
Apple Safari<18.6
18.6
Apple tvOS<18.6
18.6
Apple iOS<18.6
18.6
Apple iPadOS<18.6
18.6
Apple WatchOS<11.6
11.6
Apple iPadOS<17.7.9
17.7.9
Apple visionOS<2.6
2.6
Apple macOS Sequoia<15.6
15.6
Google Chrome<138.0.7204.157
Debian Debian Linux=11.0
Apple Safari<18.6
Apple iPadOS<18.6
Apple iPhone OS<18.6
Apple macOS<15.6
Apple visionOS<2.6
Apple WatchOS<11.6
wpewebkit WPE WebKit<2.48.0
WebKitGTK WebKitGTK<2.48.0
Remediation
Information
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Event History
Jul 15, 2025
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·07:01 PM
DescriptionSeverityAffected Software
Jul 16, 2025
News Published
via BleepingComputer·09:47 AM
News Published
via BleepingComputer·09:48 AM
Data Sourced
via Microsoft·04:31 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·04:31 PM
DescriptionAffected Software
Jul 22, 2025
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
Jul 29, 2025
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
Affected Software
Jul 30, 2025
Data Sourced
12:00 AM
SeverityWeakness
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
News Published
via BleepingComputer·04:10 PM
Aug 7, 2025
News Published
via ZDNet·06:34 PM
News Published
via ZDNet·07:38 PM
Aug 12, 2025
News Published
via ZDNet·04:01 PM
Aug 26, 2025
News Published
via ZDNet·02:20 PM
Sep 18, 2025
News Published
via BleepingComputer·07:23 AM
News Published
via The Register·06:17 PM
News Published
via The Register·06:21 PM
Nov 18, 2025
News Published
via BleepingComputer·10:13 AM
Dec 11, 2025
News Published
via BleepingComputer·08:01 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-6558?
CVE-2025-6558 has been classified as a critical vulnerability due to its potential for exploitation in sandbox escape scenarios.
2
How do I fix CVE-2025-6558?
To mitigate CVE-2025-6558, users should update to Google Chrome version 138.0.7204.157 or later.
3
Which versions of Chrome are affected by CVE-2025-6558?
CVE-2025-6558 affects Google Chrome versions earlier than 138.0.7204.157.
4
Is Microsoft Edge vulnerable to CVE-2025-6558?
Yes, Microsoft Edge (Chromium-based) also ingests Chromium and is affected unless updated to the latest version.
5
What type of vulnerability is CVE-2025-6558?
CVE-2025-6558 is a sandbox escape vulnerability that allows attackers to potentially bypass security mechanisms.