Aller au contenu
Appaloosa Scout
HIGH 8.8 KEV

CVE-2025-6558

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS v3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA Known Exploited Vulnerability

Ajouté au KEV
2025-07-22
Deadline remédiation
2025-08-12
Action requise
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Ransomware
Non

Apps mobiles affectées

Configurations CPE vulnérables

Vendor Produit Plateforme Versions CPE 2.3 URI
google chrome Android <138.0.7204.157 cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
google chrome iOS <138.0.7204.157 cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Voir sur NVD ↗ Catalogue CISA KEV ↗