CVE-2025-6558
15.07.2025, 18:15
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)Enginsight
Vendor | Product | Version |
---|---|---|
chrome | 𝑥 < 138.0.7204.157 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
chromium |
| ||||||||||||||||
webkit2gtk |
| ||||||||||||||||
wpewebkit |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
chromium-browser |
| ||||||||||||
webkitgtk |
| ||||||||||||
webkit2gtk |
| ||||||||||||
qtwebkit-source |
| ||||||||||||
qtwebkit-opensource-src |
| ||||||||||||
wpewebkit |
|
Common Weakness Enumeration
Vulnerability Media Exposure