PT-2025-29589 · Google +6 · Google Chrome +6
Clément Lecigne
+1
·
Published
2025-07-15
·
Updated
2025-08-21
·
CVE-2025-6558
10
High
Base vector | Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
## Vulnerability Report
**Name of the Vulnerable Software and Affected Versions:** Google Chrome versions prior to 138.0.7204.157, Microsoft Edge (Chromium-based), Brave, Opera. Apple Safari is also affected via WebKit.
**Description:**
This vulnerability (CVE-2025-6558) is a high-severity issue stemming from improper input validation in the ANGLE (Almost Native Graphics Layer Engine) and GPU components of Google Chrome and related Chromium-based browsers. This flaw allows a remote attacker to potentially escape the browser's sandbox, potentially leading to remote code execution. The vulnerability is actively being exploited in the wild. Apple's Safari and WebKit are also affected.
**Recommendations:**
* Update Google Chrome to version 138.0.7204.157 or later.
* Update Microsoft Edge (Chromium-based) to the latest version.
* Update Brave to the latest version.
* Update Opera to the latest version.
* Update Apple iOS to version 18.6 or later.
* Update Apple macOS to the latest version.
* Update Apple watchOS to the latest version.
* Update Apple tvOS to the latest version.
* Update Apple visionOS to the latest version.
Fix
RCE
Weakness Enumeration
Related Identifiers
Affected Products
References · 330
- https://osv.dev/vulnerability/ALSA-2025:13782 · Vendor Advisory
- https://safe-surf.ru/specialists/bulletins-nkcki/722691 · Security Note
- https://security-tracker.debian.org/tracker/CVE-2025-6558 · Vendor Advisory
- https://safe-surf.ru/specialists/bulletins-nkcki/722693 · Security Note
- https://bdu.fstec.ru/vul/2025-09437 · Security Note
- https://ubuntu.com/security/CVE-2025-43228 · Vendor Advisory
- https://safe-surf.ru/specialists/bulletins-nkcki/722692 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-7657 · Security Note
- https://osv.dev/vulnerability/ALSA-2025:13780 · Vendor Advisory
- https://ubuntu.com/security/CVE-2025-6558 · Vendor Advisory
- https://ubuntu.com/security/CVE-2025-43227 · Vendor Advisory
- https://cve.org/CVERecord?id=CVE-2025-6558 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-43212 · Security Note
- https://security-tracker.debian.org/tracker/source-package/wpewebkit · Vendor Advisory
- https://bdu.fstec.ru/vul/2025-09442 · Security Note