LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-6558: Google Chromium ANGLE and GPU Improper Input Validation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 22, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Aug 12, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-6558 to its Known Exploited Vulnerabilities catalog on Jul 22, 2025, with a federal patch deadline of Aug 12, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page…

CVE-2025-6558 is an improper input validation flaw in Google Chromium's ANGLE and GPU components. A remote attacker can potentially achieve a sandbox escape by luring a user to a crafted HTML page. Because Chromium underpins multiple browsers, the issue can affect Google Chrome, Microsoft Edge, Opera, and other products that embed the same engine. Sandbox escape matters: once an attacker leaves the browser's restricted environment they can more easily reach the host, steal credentials, or move laterally.

Defenders should treat this as a high-priority browser vulnerability. Confirm exact impact, fixed builds, and any configuration notes against the vendor advisory before acting.

How it works

The weakness is classified as CWE-20 (Improper Input Validation). ANGLE (Almost Native Graphics Layer Engine) and the GPU process handle graphics and rendering tasks that browsers isolate for security. When input supplied by web content is not validated correctly, a malicious page can trigger unexpected behavior inside those components.

An attacker hosts or delivers a specially crafted HTML page. When the page is rendered, the invalid input reaches the ANGLE/GPU path and can be abused to break out of the browser sandbox. Public detail on the precise trigger is limited; treat any claim of exploit mechanics or reliability as unconfirmed until the vendor advisory or reliable analysis provides it. The attack requires the victim to process the malicious content, typically by visiting a page or opening a file that loads it.

Am I affected? How to find it in your systems

Chromium-based browsers are common on endpoints, VDI, kiosks, and developer workstations. Inventory every browser that embeds Chromium: Google Chrome, Microsoft Edge, Opera, and any Chromium-derived or Electron applications that ship their own browser engine.

Confirm affected components and versions only from the official vendor advisory.

How to remediate

Patch first. Apply the vendor-supplied updates for Chromium and for every product that embeds it, following the instructions in the official advisory. CISA guidance is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Hardening for this class of flaw includes keeping the browser sandbox enabled (the default), restricting untrusted content, and ensuring GPU process isolation features remain on. Specific configuration toggles must be confirmed in the vendor documentation.

If you can't patch immediately

Reduce exposure until the update can be applied.

These controls lower likelihood and impact but do not replace the vendor patch.

If your data may have been exposed

Actively exploited browser sandbox escapes can lead to credential theft, malware installation, or further compromise of the host. Known ransomware use of this specific CVE is not documented. If you suspect exploitation, isolate the endpoint, collect memory and disk artifacts, rotate credentials that may have been present in the browser session, and review access logs for lateral movement. You can run a free exposure scan of your email addresses against known breach data to check whether related accounts already appear in public dumps, then force password resets and enable multi-factor authentication where missing.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedGoogle · Chromium
WeaknessCWE-20
Added to CISA KEVJul 22, 2025
Federal patch deadlineAug 12, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities