CVE-2025-6558
9.5 CISA KEVGoogle · Chromium
Google Chrome contains an improper input validation vulnerability in the ANGLE and GPU components that allows a remote attacker to achieve a sandbox escape via a crafted HTML page.
Executive summary
This critical vulnerability in Google Chrome is confirmed to be actively exploited in the wild and allows remote attackers to bypass sandbox protections via a malicious web page.
Vulnerability
The flaw stems from insufficient validation of untrusted input within the ANGLE and GPU modules. An unauthenticated remote attacker can trigger this vulnerability by enticing a user to visit a specially crafted HTML page, leading to a sandbox escape.
Business impact
The ability to escape the browser sandbox poses a severe risk to organizational security, as it grants an attacker the potential to execute code directly on the underlying host operating system. Given the CVSS score of 9.5 and evidence of active exploitation, this vulnerability presents a critical threat to data integrity, system confidentiality, and overall endpoint security.
Remediation
Immediate Action: Update all instances of Google Chrome to version 138.0.7204.157 or later immediately to incorporate the necessary security patches.
Proactive Monitoring: Monitor endpoint security logs for unusual process spawning or unexpected system calls originating from the browser process.
Compensating Controls: While no direct WAF rule can prevent a browser-level sandbox escape, ensure that endpoint detection and response (EDR) solutions are configured to alert on anomalous child processes initiated by the browser.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Due to the confirmed active exploitation of this vulnerability and its potential for full system compromise, this issue must be treated as a top-priority security event. Organizations should prioritize the deployment of the Google Chrome update across all managed workstations and mobile devices to mitigate the risk of remote code execution.
More Google CVEs all →
History
- Disclosed CVE record published
- Published in the daily brief high section, carried in 2 daily briefs, Jul 15 to Jul 16
- Published in the daily brief kev section, carried in 3 daily briefs, Jul 23 to Jul 25
- Published in the daily brief critical section, carried in 5 daily briefs, Jul 28 to Aug 1
- Published in the daily brief critical section, carried in 7 daily briefs, Aug 4 to Aug 11
- Analyst report written
- Fix documented version 138.0.7204.157 per CVE record