CVE-2025-6558: Google Chromium ANGLE and GPU Improper Input Validation Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2025-07-22. EPSS: 9.5% chance of exploitation in the next 30 days.

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Affected products

  • Apple iPadOS: before 18.6 (fixed in 18.6)
  • Apple iPhone OS: before 18.6 (fixed in 18.6)
  • Apple macOS: before 15.6 (fixed in 15.6)
  • Apple Safari: before 18.6 (fixed in 18.6)
  • Apple visionOS: before 2.6 (fixed in 2.6)
  • Apple watchOS: before 11.6 (fixed in 11.6)
  • Debian Debian Linux: version 11.0 only
  • Google Chrome: before 138.0.7204.157 (fixed in 138.0.7204.157)
  • WebKitGTK WebKitGTK: before 2.48.5 (fixed in 2.48.5)
  • Wpewebkit Wpe Webkit: before 2.48.5 (fixed in 2.48.5)

Published 2025-07-15. Last modified 2026-10-01.