CVE-2025-6558: Google Chromium ANGLE and GPU Improper Input Validation Vulnerability
Accessibility. A logic issue was addressed with improved checks.
Other sources
Accessibility. The issue was addressed by adding additional logic.
— Apple
Admin Framework. A path handling issue was addressed with improved validation.
— Apple
afclip. The issue was addressed with improved memory handling.
— Apple
AMD. A race condition was addressed with improved state handling.
— Apple
AppleMobileFileIntegrity. A downgrade issue was addressed with additional code-signing restrictions.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.7.9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.6 - Upgrade
Upgrade
Google Chrometo a version that resolves this vulnerability.Fixed in 138.0.7204.157 - Compensating control
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-43186
- CVE-2025-43223
- CVE-2025-43277
- CVE-2025-43210
- CVE-2025-43230
- CVE-2025-43209
- CVE-2025-43226
- CVE-2025-43282
- CVE-2025-7425
- CVE-2025-7424
- CVE-2025-43234
- CVE-2025-43224
- CVE-2025-43221
- CVE-2025-31281
- CVE-2025-6965
- CVE-2025-43227
- CVE-2025-31278
- CVE-2025-31277
- CVE-2025-31273
- CVE-2025-43214
- CVE-2025-43213
- CVE-2025-43212
- CVE-2025-43211
- CVE-2025-43265
- CVE-2025-43216
- CVE-2025-6558
- CVE-2025-31229
- CVE-2025-43217
- CVE-2025-43202
- CVE-2025-31276
- CVE-2025-43280
- CVE-2025-43228
- CVE-2025-43222
- CVE-2025-43220
- CVE-2025-31279
- CVE-2025-24224
- CVE-2025-43225
- CVE-2025-24220
- CVE-2025-43191
- CVE-2025-43244
- CVE-2025-31243
- CVE-2025-43253
- CVE-2025-43249
- CVE-2025-43248
- CVE-2025-43245
- CVE-2025-43281
- CVE-2025-43257
- CVE-2025-43273
- CVE-2025-43195
- CVE-2025-43199
- CVE-2025-43313
- CVE-2025-43267
- CVE-2025-43187
- CVE-2025-43188
- CVE-2025-43198
- CVE-2025-43254
- CVE-2025-43261
- CVE-2025-43255
- CVE-2025-43284
- CVE-2025-43276
- CVE-2025-43268
- CVE-2025-43196
- CVE-2025-43192
- CVE-2025-31275
- CVE-2025-43264
- CVE-2025-43219
- CVE-2025-31280
- CVE-2025-43218
- CVE-2025-43215
- CVE-2025-43275
- CVE-2025-43270
- CVE-2025-43266
- CVE-2025-43260
- CVE-2025-43247
- CVE-2025-43194
- CVE-2025-43232
- CVE-2025-43236
- CVE-2025-43235
- CVE-2025-43274
- CVE-2025-24188
- CVE-2025-43241
- CVE-2025-43233
- CVE-2025-43193
- CVE-2025-43250
- CVE-2025-43197
- CVE-2025-43239
- CVE-2025-43243
- CVE-2025-43246
- CVE-2025-43256
- CVE-2025-43206
- CVE-2025-43251
- CVE-2025-43185
- CVE-2025-43189
- CVE-2025-43237
- CVE-2025-43229
- CVE-2025-43240
- CVE-2025-43259
- CVE-2025-43238
- CVE-2025-43252
Frequently Asked Questions
What is the severity of CVE-2025-6558?
CVE-2025-6558 has been classified as a critical vulnerability due to its potential for exploitation in sandbox escape scenarios.
How do I fix CVE-2025-6558?
To mitigate CVE-2025-6558, users should update to Google Chrome version 138.0.7204.157 or later.
Which versions of Chrome are affected by CVE-2025-6558?
CVE-2025-6558 affects Google Chrome versions earlier than 138.0.7204.157.
Is Microsoft Edge vulnerable to CVE-2025-6558?
Yes, Microsoft Edge (Chromium-based) also ingests Chromium and is affected unless updated to the latest version.
What type of vulnerability is CVE-2025-6558?
CVE-2025-6558 is a sandbox escape vulnerability that allows attackers to potentially bypass security mechanisms.