Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4276-1 | webkit2gtk security update |
Debian DSA |
DSA-5963-1 | chromium security update |
Debian DSA |
DSA-5978-1 | webkit2gtk security update |
EUVD |
EUVD-2025-21546 | Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) |
Ubuntu USN |
USN-7702-1 | WebKitGTK vulnerabilities |
Thu, 06 Nov 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webkitgtk
Webkitgtk webkitgtk Wpewebkit Wpewebkit wpe Webkit |
|
| CPEs | cpe:2.3:a:webkitgtk:webkitgtk:*:*:*:*:*:*:*:* cpe:2.3:a:wpewebkit:wpe_webkit:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Webkitgtk
Webkitgtk webkitgtk Wpewebkit Wpewebkit wpe Webkit |
Tue, 04 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 04 Nov 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple ipados Apple iphone Os Apple macos Apple safari Apple visionos Apple watchos Debian Debian debian Linux |
|
| CPEs | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Apple
Apple ipados Apple iphone Os Apple macos Apple safari Apple visionos Apple watchos Debian Debian debian Linux |
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 03 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 05 Aug 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | chromium-browser: Chromium insufficient validation | |
| Weaknesses | CWE-76 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 29 Jul 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Tue, 22 Jul 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
kev
|
Wed, 16 Jul 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google chrome |
|
| CPEs | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Google
Google chrome |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
Tue, 15 Jul 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 15 Jul 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | |
| Weaknesses | CWE-20 | |
| References |
|
Status: PUBLISHED
Assigner: Chrome
Published:
Updated: 2026-02-26T17:50:40.914Z
Reserved: 2025-06-23T22:30:38.590Z
Link: CVE-2025-6558
Updated: 2025-11-04T21:14:50.202Z
Status : Analyzed
Published: 2025-07-15T18:15:24.533
Modified: 2025-11-06T14:52:01.530
Link: CVE-2025-6558
OpenCVE Enrichment
Updated: 2025-07-16T21:35:22Z
Debian DLA
Debian DSA
EUVD
Ubuntu USN