CVE-2025-6558

HIGH KEV

Google Chrome <138.0.7204.157 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-6558 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added July 22, 2025. EIP tracks 2 public exploits from researchers including DevBuiHieu, gmh5225.

AI-analyzed exploit summary The repository contains only a README.md with a title and no substantive content or exploit code. No technical details or proof-of-concept are provided.

Description

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Exploits (2)

nomisec STUB 7 stars
by DevBuiHieu · client-side
https://github.com/DevBuiHieu/CVE-2025-6558-Proof-Of-Concept

The repository contains only a README.md with a title and no substantive content or exploit code. No technical details or proof-of-concept are provided.

Classification
Stub 10%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unknown
No auth needed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 1 stars
by gmh5225 · poc
https://github.com/gmh5225/CVE-2025-6558-exp

This repository contains a writeup for CVE-2025-6558, a critical sandbox escape vulnerability in Google Chrome's ANGLE/GPU components. The vulnerability allows remote code execution via malicious WebGL/HTML content, but no actual exploit code is provided.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: Google Chrome < 138.0.7204.157
No auth needed
Prerequisites: User visits a malicious webpage with crafted WebGL/HTML content
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 8.8
EPSS 0.0028
EPSS Percentile 51.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2025-07-22
VulnCheck KEV 2025-07-15
ENISA EUVD EUVD-2025-21546
CWE
CWE-20
Status published
Products (10)
apple/ipados < 18.6
apple/iphone_os < 18.6
apple/macos < 15.6
apple/safari < 18.6
apple/visionos < 2.6
apple/watchos < 11.6
debian/debian_linux 11.0
google/chrome < 138.0.7204.157
webkitgtk/webkitgtk < 2.48.0
wpewebkit/wpe_webkit < 2.48.0
Published Jul 15, 2025
KEV Added Jul 22, 2025
Tracked Since Feb 18, 2026