Junglewise Threat Intelligence

CVE-2025-6558: Google Chromium improper input validation in ANGLE and GPU

CVE-2025-6558 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2025-07-22

Technologies: Google Chrome, Microsoft Edge, Opera Software Opera, Google Chromium. Vendors: Google, Microsoft, Opera Software.

Executive brief

Google Chrome and other Chromium-based browsers (like Microsoft Edge) are affected by a security flaw in their graphics processing components. An attacker can exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to bypass the browser's security sandbox. This could lead to unauthorized access to the user's computer or sensitive data.

Technical details

An improper input validation vulnerability exists in the ANGLE (Almost Native Graphics Layer Engine) and GPU components of Google Chromium. The flaw is triggered when the browser processes untrusted input from a malicious HTML page. A remote, unauthenticated attacker can exploit this to achieve a sandbox escape, potentially leading to arbitrary code execution on the underlying operating system. This vulnerability has been reported as exploited in the wild and is addressed in Chrome version 138.0.7204.157 and later.

Affected products

  • Google Chrome prior to 138.0.7204.157
  • Microsoft Edge
  • Opera Software Opera

Timeline

  • 2025-07-15: patched: Chrome stable channel update released
  • 2025-07-22: disclosed: Initial NVD publication and CISA KEV addition
  • 2025-07-22: exploited: Confirmed active exploitation by CISA

Related threats