🟒 CVE-2025-6558

CVE-2025-6558 is a Google Chrome vulnerability allowing sandbox escape via crafted HTML pages. While actively exploited and on CISA KEV, it requires user interaction to visit malicious websites, making it unsuitable for T1190 direct network exploitation.

← Back to Overview
LOW_RISK
Risk Level
8.8
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1189 β€” Drive-by Compromise
ATT&CK Technique
VERY_LOW
Deployment Risk
No
Ransomware

πŸ“‹ Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: USER_INTERACTION

CVE Published: 2025-07-15

Added to CISA KEV: 2025-07-22 7 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

πŸ” Web Intelligence (Kagi Β· 2025-09-06)

CVE-2025-6558 is a critical zero-day vulnerability that primarily affects web browsers such as Google Chrome and Apple Safari [1][2]. It stems from improper input validation in Chromium's ANGLE and GPU components [3][4]. This allows for remote exploitation through crafted HTML pages, potentially leading to a sandbox escape [5][1]. The vulnerability has been actively exploited in the wild and has been added to CISA's Known Exploited Vulnerabilities Catalog [6][7].

Here's a breakdown of the details:

  • Internet-facing applications or services: CVE-2025-6558 affects web browsers, which are inherently internet-facing applications [1][2].
  • Evidence of active exploitation in the wild: There is confirmed active exploitation of CVE-2025-6558 [6][7]. Google has acknowledged that an exploit for this vulnerability exists in the wild [6].
  • Attack vectors and exploitation methods: The vulnerability is exploited through a crafted HTML page that leverages the improper input validation in the ANGLE and GPU components of Chromium [5][1]. This can lead to a sandbox escape, allowing attackers to execute code outside the browser's security sandbox [5][1].
  • Whether it's been used in targeted attacks: While specific details about targeted attacks are not extensively provided, the nature of a zero-day often implies sophisticated use [5].
  • CISA Known Exploited Vulnerabilities status: CISA has added CVE-2025-6558 to its Known Exploited Vulnerabilities Catalog, indicating that it is actively being exploited [8][9].
  • Technical details about internet exploitability: The vulnerability exists due to incorrect validation of untrusted input in the ANGLE and GPU components of web browsers [3][1]. An attacker can exploit this by crafting a malicious HTML page that, when opened in a vulnerable browser, can trigger the vulnerability and potentially allow for a sandbox escape [5][1].

Sources

  1. Apple Patches Safari Vulnerability Also Exploited as Zero-Day in...

    The vulnerability, tracked as CVE-2025-6558 (CVSS score: 8.8), is an incorrect validation of untrusted input in the browser's ANGLE and GPU components that could result in a sandbox escape via a crafted HTML page.

  2. CVE-2025-6558: Chrome Zero-Day Exploit Uncovered

    CVE-2025-6558 is a Chrome zero-day exploited via ANGLE GPU input flaw. Learn how the attack works, who's at risk, and how to secure your browser.

  3. Google Chrome 0-day Vulnerability Actively Exploited in the Wild

    The CVE-2025-6558 vulnerability stems from incorrect validation of untrusted input in ANGLE and GPU components.Given the active exploitation of CVE-2025-6558, delaying this update could expose users to significant security risks.

  4. Your quick strike cyber update for August 1, 2025 1:21 PM - SparTech...

    A newly discovered vulnerability, tracked as CVE-2025-6558, affecting Chrome’s ANGLE and GPU components, has been actively exploited in the wild.Attack Patterns and Social Engineering Methods. Technical Impact of Backup Compromise. Defensive Strategies.

  5. CVE-2025-6558 Impact, Exploitability, and Mitigation Steps - Wiz

    Understand the critical aspects of CVE-2025-6558 with a detailed vulnerability assessment, exploitation potential, affected technologies, and remediation guidance.