CVE CVE

CVE-2025-6558

CISA Known Exploited Vulnerability (KEV)

Google Chromium ANGLE and GPU Improper Input Validation Vulnerability

July 22, 2025

August 12, 2025

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Description

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Weakness Enumeration

CWE-ID CWE Name

CWE-20
Improper Input Validation

Known Affected Software Configurations


cpe:2.3:a:google:chrome:136.0.7103.59:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:137.0.7151.103:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:132.0.6834.110:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:137.0.7151.119:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:138.0.7204.157:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:137.0.7151.68:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:138.0.7204.49:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:138.0.7204.96:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:135.0.7049.95:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:132.0.6834.159:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:136.0.7103.92:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:136.0.7103.113:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:137.0.7151.55:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:133.0.6943.126:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:134.0.6998.88:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:133.0.69943.98:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:133.0.6943.98:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:133.0.6943.53:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:134.0.6998:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:131.0.6778.204:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:131.0.6778.264:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:135.0.7049.52:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:134.0.6998.177:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:134.0.6998.35:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:134.0.6998.117:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:131.0:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:127.0:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:126.0:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:125.0:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:124.0:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:130.0:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:128.0:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:132.0.6834.83:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:133.0:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:129.0:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:107.0.5304.87:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:132.0:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:131.0.6778.69:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:131.0.6778.139:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:131.0.6778.108:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:130.0.6723.116:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:129.0.6668.70:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:128.0.6537.0:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:124.0.6367.155:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:129.0.6668.89:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:129.0.6668.100:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:130.0.6723.92:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:126.0.6478.126:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:124.0.6367.118:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:125.0.6422.76:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:125.0.6422.141:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:126.0.6478.182:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:123.0.6312.122:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:128.0.6613.119:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:122.0.6261.94:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:122.0.6261.128:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:122.0.6261.111:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:123.0.6312.86:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:130.0.6723.69:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:130.0.6723.58:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:128.0.6613.84:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:128.0.6613.137:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:128.0.6613.113:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:129.0.6668.58:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:125.0.6422.60:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:125.0.6422.113:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:125.0.6422.112:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:124.0.6367.207:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:124.0.6367.201:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:117.0.5938.132:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:116.0.5845.179:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:116.0.5845.187:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:32.0.1700.107:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:127.0.6533.88:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:127.0.6533.99:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:127.0.6533.72:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:89.0.4389.128:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:90.0.4430.85:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:119.0.6045.105:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:120.0.6099.224:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:122.0.6261.57:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:121.0.6167.139:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:126.0.6478.54:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:103.0.5060.114:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:126.0.6478.114:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:124.0.6367.78:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:54.0.2840.90:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:54.0.2840.85:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:49.0.2623.108:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:114.0.5735.110:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:114.0.5735.106:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:57.0.2987.108:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:105.0.5195.102:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:107.0.5304.121:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:124.0.6367.60:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:123.0.6312.58:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:123.0.6312.105:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:121.0.6167.160:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:120.0.6099.62:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:121.0.6167.85:*:*:*:*:*:*:*

Details

Source:
NVD
Published:
Updated:

Risk information

CVSS v3

Base score:
8.8
Severity:

HIGH

Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v2

Not defined