CVE-2025-6558
גבוהה 8.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Google Chromium ANGLE and GPU Improper Input Validation Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 9% (אחוזון 100) נכון ל-26/7/2026
- CWE
- CWE-20
מוצרים מושפעים
google: chrome; debian: debian linux; apple: safari; apple: ipados; apple: iphone os; apple: macos; apple: visionos; apple: watchos; wpewebkit: wpe webkit; webkitgtk: webkitgtk
קישורים
- https://chromereleases.googleblog.com/2025/07/stable-channel-update-for-deskto… Release Notes
- https://issues.chromium.org/issues/427162086 Issue TrackingPermissions Required
- http://seclists.org/fulldisclosure/2025/Aug/0 Third Party Advisory
- http://seclists.org/fulldisclosure/2025/Jul/30 Third Party Advisory
- http://seclists.org/fulldisclosure/2025/Jul/32 Third Party Advisory
- http://seclists.org/fulldisclosure/2025/Jul/35 Third Party Advisory
- http://seclists.org/fulldisclosure/2025/Jul/37 Third Party Advisory
- http://www.openwall.com/lists/oss-security/2025/08/02/1 Mailing List
- https://lists.debian.org/debian-lts-announce/2025/08/msg00015.html Mailing ListThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource