CVE-2025-6558
KEV
🔴 Łataj teraz
Niewystarczająca walidacja danych w Google Chrome umożliwia zdalne obejście piaskownicy.
CVSS
8.8
EPSS
9.6%
Exploit
weaponized
Vendor
apple
Opis źródłowy (NVD)
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.8 |
| CISA KEV (aktywnie wykorzystywane) | Tak |
| FIRST EPSS (prawdopodobieństwo exploita) | 9.6% |
| Opublikowano (NVD) | 2025-07-15 18:15:24 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-01 02:16:52 UTC |
Referencje
- https://chromereleases.googleblog.com/2025/07/stable-channel-update-for-desktop_15.html ([email protected]) [Release Notes]
- https://issues.chromium.org/issues/427162086 ([email protected]) [Issue Tracking, Permissions Required]
- http://seclists.org/fulldisclosure/2025/Aug/0 (af854a3a-2127-422b-91ae-364da2661108) [Third Party Advisory]
- http://seclists.org/fulldisclosure/2025/Jul/30 (af854a3a-2127-422b-91ae-364da2661108) [Third Party Advisory]
- http://seclists.org/fulldisclosure/2025/Jul/32 (af854a3a-2127-422b-91ae-364da2661108) [Third Party Advisory]
- http://seclists.org/fulldisclosure/2025/Jul/35 (af854a3a-2127-422b-91ae-364da2661108) [Third Party Advisory]
- http://seclists.org/fulldisclosure/2025/Jul/37 (af854a3a-2127-422b-91ae-364da2661108) [Third Party Advisory]
- http://www.openwall.com/lists/oss-security/2025/08/02/1 (af854a3a-2127-422b-91ae-364da2661108) [Mailing List]
- http://www.openwall.com/lists/oss-security/2026/09/30/18 (af854a3a-2127-422b-91ae-364da2661108)
- https://lists.debian.org/debian-lts-announce/2025/08/msg00015.html (af854a3a-2127-422b-91ae-364da2661108) [Mailing List, Third Party Advisory]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-6558 (134c704f-9b21-4f2e-91b3-4a467353bcc0) [US Government Resource]