Описание
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
chromium | fixed | 138.0.7204.157-1 | package | |
chromium | end-of-life | bullseye | package | |
webkit2gtk | fixed | 2.48.5-1 | package | |
wpewebkit | fixed | 2.48.5-1 | package | |
wpewebkit | ignored | trixie | package | |
wpewebkit | ignored | bookworm | package | |
wpewebkit | ignored | bullseye | package |
Примечания
https://webkitgtk.org/security/WSA-2025-0005.html
EPSS
Связанные уязвимости
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Chromium: CVE-2025-6558 Incorrect validation of untrusted input in ANGLE and GPU
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
EPSS