Executive brief
Google Chrome and other Chromium-based browsers (like Microsoft Edge) are affected by a security flaw in their graphics processing components. An attacker can exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to bypass the browser's security sandbox. This could lead to unauthorized access to the user's computer or sensitive data.
Technical details
An improper input validation vulnerability exists in the ANGLE (Almost Native Graphics Layer Engine) and GPU components of Google Chromium. The flaw is triggered when the browser processes untrusted input from a malicious HTML page. A remote, unauthenticated attacker can exploit this to achieve a sandbox escape, potentially leading to arbitrary code execution on the underlying operating system. This vulnerability has been reported as exploited in the wild and is addressed in Chrome version 138.0.7204.157 and later.
Affected products
- Google Chrome prior to 138.0.7204.157
- Microsoft Edge
- Opera Software Opera
Timeline
- 2025-07-15: patched: Chrome stable channel update released
- 2025-07-22: disclosed: Initial NVD publication and CISA KEV addition
- 2025-07-22: exploited: Confirmed active exploitation by CISA