CVE-2025-6558

Name
CVE-2025-6558
Description
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
chrome-cve-admin@google.com https://chromereleases.googleblog.com/2025/07/stable-channel-update-for-desktop_15.html
chrome-cve-admin@google.com https://issues.chromium.org/issues/427162086
134c704f-9b21-4f2e-91b3-4a467353bcc0 https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-6558
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2025/08/msg00015.html
af854a3a-2127-422b-91ae-364da2661108 http://seclists.org/fulldisclosure/2025/Aug/0
af854a3a-2127-422b-91ae-364da2661108 http://seclists.org/fulldisclosure/2025/Jul/30
af854a3a-2127-422b-91ae-364da2661108 http://seclists.org/fulldisclosure/2025/Jul/32
af854a3a-2127-422b-91ae-364da2661108 http://seclists.org/fulldisclosure/2025/Jul/35
af854a3a-2127-422b-91ae-364da2661108 http://seclists.org/fulldisclosure/2025/Jul/37
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/08/02/1

Match rules

CPE URI Source package Min version Max version
chrome >= 0 < 138.0.7204.157

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
qt6-qtwebengine edge-community 6.9.1-r3 Bart Ribbers <bribbers@disroot.org> fixed
qt6-qtwebengine 3.22-community 6.8.3-r1 Bart Ribbers <bribbers@disroot.org> fixed