Описание
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип | 
|---|---|---|---|---|
| chromium | fixed | 138.0.7204.157-1 | package | |
| chromium | end-of-life | bullseye | package | |
| webkit2gtk | fixed | 2.48.5-1 | package | |
| wpewebkit | fixed | 2.48.5-1 | package | |
| wpewebkit | ignored | trixie | package | |
| wpewebkit | ignored | bookworm | package | |
| wpewebkit | ignored | bullseye | package | 
Примечания
https://webkitgtk.org/security/WSA-2025-0005.html
EPSS
Связанные уязвимости
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Chromium: CVE-2025-6558 Incorrect validation of untrusted input in ANGLE and GPU
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
EPSS