CVE-2025-6558Active Exploitation(apple / chrome)

MEDIUMCVSS 8.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for apple chrome systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

4.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-08-12. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-20

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • debian_linux
  • ipados
  • iphone_os

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-04-13); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
chromedebian_linuxipadosiphone_osmacossafarivisionoswatchoswebkitgtkwpe_webkit

1 version affected across 10 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-13: 1Mentions · 2026-10-02: 1Active Exploitation · 2026-04-13: 1Technical Details · 2026-04-13: 104-1310-02
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • つみかさね@tsumikasanedev

    Google ChromeのANGLE/GPUに入力検証不備(CVE-2025-6558)。細工されたWebページを開くだけでレンダラのサンドボックスを脱出される恐れ。放置するとブラウザ由来のリスクが端末全体へ広がりかねません。138.0.7204.157で修正済み。

    1000038
    4 followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [HIGH] Active exploitation detected: CVE-2025-6558 Exploit in the wild confirmed for CVE-2025-6558 (CVSS null). Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. Thi... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    A confirmed live exploitation of CVE-2025-6558 involving improper input validation in Chromium's ANGLE and GPU components has been reported.

    00000222
    5.6K followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
Appapplesafari---
OSapplevisionos---
OSapplewatchos---
OSdebiandebian_linux11.0--
Appgooglechrome---
Appwebkitgtkwebkitgtk---
Appwpewebkitwpe_webkit---

Explore more