Google patches Chrome zero-day allowing sandbox escape

Google patches Chrome zero-day allowing sandbox escape

Google has released a critical security update for its Chrome browser, addressing six vulnerabilities, including one high-severity flaw that has been actively exploited in the wild.

The most serious issue, tracked as CVE-2025-6558, affects Chrome versions prior to 138.0.7204.157. The flaw stems from insufficient validation of untrusted input in ANGLE and GPU, components responsible for translating graphics commands for the browser’s rendering processes. Specifically, ANGLE (Almost Native Graphics Layer Engine) is a graphics abstraction layer that helps Chrome run WebGL content across different platforms.

While technical details of the exploit have not yet been disclosed, Google confirmed that the vulnerability has been observed in active attacks. Users are strongly advised to update Chrome immediately to the latest version to mitigate potential threats. The company did not provide any additional information on threat actors or the nature of attacks exploiting this flaw.


Back to the list

Latest Posts

UK sanctions Russian hackers for malicious hybrid operations

UK sanctions Russian hackers for malicious hybrid operations

Additionally, UK’s NCSC has publicly attributed the deployment of a sophisticated new malware dubbed ‘AUTHENTIC ANTICS’ to the APT28 threat actor long thought to be a unit of the GRU (Military Unit 26165).
21 July 2025
APT28 targets Ukrainian defense sector using AI-powered Lamehug malware

APT28 targets Ukrainian defense sector using AI-powered Lamehug malware

Lamehug is integrated with Qwen 2.5-Coder-32B-Instruct, a powerful LLM accessed via the HuggingFace API.
21 July 2025
Microsoft SharePoint flaw actively exploited in large-scale cyberattacks

Microsoft SharePoint flaw actively exploited in large-scale cyberattacks

The zero-day flaw, tracked as CVE-2025-53770, allows unauthorized attackers to remotely execute code on vulnerable systems.
21 July 2025