Google has issued an urgent warning about a critical vulnerability in Google Chromium, designated as CVE-2025-6558. The vulnerability, caused by improper input validation in Chromium’s ANGLE and GPU components, allows attackers to execute sandbox escape attacks through malicious HTML. This vulnerability affects all Chromium-based browsers, including Google Chrome, Microsoft Edge, and Opera, potentially putting millions of users at risk. The flaw enables remote code execution and bypasses browser security controls, making it a significant threat to users' data and system integrity.
Source: https://cybersecuritynews.com/cisa-google-chromium-0-day/
TPRM report: https://scoringcyber.rankiteo.com/company/google
"id": "goo354072525",
"linkid": "google",
"type": "Vulnerability",
"date": "7/2025",
"severity": "25",
"impact": "1",
"explanation": "Attack without any consequences"
{'affected_entities': [{'industry': 'Technology',
'name': ['Google', 'Microsoft', 'Opera'],
'type': 'Software Company'}],
'attack_vector': ['Malicious HTML pages', 'Improper Input Validation'],
'date_publicly_disclosed': '2025-07-22',
'description': 'CISA has issued an urgent warning about a critical '
'vulnerability in Google Chromium that threat actors are '
'actively exploiting. The vulnerability, designated as '
'CVE-2025-6558, poses a significant security risk to millions '
'of users across multiple web browsers that utilize the '
'Chromium engine.',
'impact': {'systems_affected': ['Google Chrome',
'Microsoft Edge',
'Opera',
'All Chromium-based browsers']},
'initial_access_broker': {'entry_point': 'Malicious HTML pages'},
'motivation': ['Install malware',
'Steal sensitive data',
'Establish persistent access'],
'post_incident_analysis': {'corrective_actions': ['Apply patches',
'Update to the latest '
'browser versions'],
'root_causes': 'Improper input validation within '
'Chromium’s ANGLE and GPU '
'components'},
'recommendations': ['Prioritize immediate updates to the latest browser '
'versions'],
'references': [{'date_accessed': '2025-07-22', 'source': 'CISA'}],
'response': {'containment_measures': ['Apply vendor-provided mitigations',
'Discontinue use of affected products '
'if patches are unavailable'],
'remediation_measures': ['Apply patches',
'Update to the latest browser '
'versions']},
'title': 'Critical Vulnerability in Google Chromium (CVE-2025-6558)',
'type': 'Vulnerability Exploitation',
'vulnerability_exploited': 'CVE-2025-6558'}