
Google ChromeのANGLE/GPUに入力検証不備(CVE-2025-6558)。細工されたWebページを開くだけでレンダラのサンドボックスを脱出される恐れ。放置するとブラウザ由来のリスクが端末全体へ広がりかねません。138.0.7204.157で修正済み。
Exploitation ongoing with high activity in latest observed window (1 mentions)
Recommended action window: Immediate (within 24h)
NVD description
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-08-12. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Priority
MEDIUM
Exploitation
ACTIVE
PoC
NONE
Patch
NONE
Momentum
STABLE
If you run products in this scope, you should treat this CVE as relevant to your environment.
1 version affected across 10 products

Google ChromeのANGLE/GPUに入力検証不備(CVE-2025-6558)。細工されたWebページを開くだけでレンダラのサンドボックスを脱出される恐れ。放置するとブラウザ由来のリスクが端末全体へ広がりかねません。138.0.7204.157で修正済み。

🚨 [HIGH] Active exploitation detected: CVE-2025-6558 Exploit in the wild confirmed for CVE-2025-6558 (CVSS null). Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. Thi... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity
Post summary
A confirmed live exploitation of CVE-2025-6558 involving improper input validation in Chromium's ANGLE and GPU components has been reported.
10 of 10 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| OS | apple | ipados | - | - | - |
| OS | apple | iphone_os | - | - | - |
| OS | apple | macos | - | - | - |
| App | apple | safari | - | - | - |
| OS | apple | visionos | - | - | - |
| OS | apple | watchos | - | - | - |
| OS | debian | debian_linux | 11.0 | - | - |
| App | chrome | - | - | - | |
| App | webkitgtk | webkitgtk | - | - | - |
| App | wpewebkit | wpe_webkit | - | - | - |