Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Is CVE-2025-6558 exploited?
Listed in the CISA KEV catalog on 2025-07-22.
Federal remediation due 2025-08-12.
Past that date by 368 days.
EPSS puts exploitation in the next 30 days at 9%.
Public exploit code: none found in monitored sources.