CVE-2025-6558
15.07.2025, 18:15
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)Enginsight
| Vendor | Product | Version |
|---|---|---|
| chrome | 𝑥 < 138.0.7204.157 | |
| debian | debian_linux | 11.0 |
| apple | safari | 𝑥 < 18.6 |
| apple | ipados | 𝑥 < 18.6 |
| apple | iphone_os | 𝑥 < 18.6 |
| apple | macos | 𝑥 < 15.6 |
| apple | visionos | 𝑥 < 2.6 |
| apple | watchos | 𝑥 < 11.6 |
| wpewebkit | wpe_webkit | 𝑥 < 2.48.0 |
| webkitgtk | webkitgtk | 𝑥 < 2.48.0 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| chromium |
| ||||||||||||||||
| webkit2gtk |
| ||||||||||||||||
| wpewebkit |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| chromium-browser |
| ||||||||||||
| webkitgtk |
| ||||||||||||
| webkit2gtk |
| ||||||||||||
| qtwebkit-source |
| ||||||||||||
| qtwebkit-opensource-src |
| ||||||||||||
| wpewebkit |
|
Common Weakness Enumeration
References