Source: www.securityweek.com – Author: Ionut Arghire
Google on Tuesday announced a fresh set of Chrome security updates that resolve six vulnerabilities, including one exploited in the wild.
The zero-day bug, tracked as CVE-2025-6558, is described as an incorrect validation of untrusted input in the browser’s ANGLE and GPU components.
ANGLE, short for Almost Native Graphics Layer Engine, is an open source, cross-platform graphics engine used as the default WebGL backend in both Chrome and Firefox on Windows. Chrome primarily uses the GPU component to render graphics and video content on webpages.
According to a NIST advisory, successful exploitation of the flaw could allow remote attackers to escape the browser’s sandbox via crafted HTML pages.
“Google is aware that an exploit for CVE-2025-6558 exists in the wild,” Google notes in its advisory.
This is the fifth zero-day patched by Google in the Chrome browser to date this year.
As usual, the internet giant refrained from sharing details on the observed attacks, but noted that the security defect was reported by Clément Lecigne and Vlad Stolyarov of Google’s Threat Analysis Group.
TAG researchers are known for uncovering vulnerabilities exploited by commercial spyware vendors, including some in the Chrome browser, and this could be the case for the newly disclosed CVE as well.
Advertisement. Scroll to continue reading.
The fresh Chrome update addresses two other bugs reported by external researchers, namely CVE-2025-7656, an integer overflow issue in the V8 JavaScript engine, and CVE-2025-7657, a use-after-free flaw in WebRTC.
Google says it paid a $7,000 reward for the V8 defect, but has yet to disclose the amount handed out for the WebRTC issue. Per the company’s rules, no bug bounty will be awarded for the internally discovered zero-day.
The latest Chrome iteration is now rolling out as versions 138.0.7204.157/.158 for Windows and macOS, and as version 138.0.7204.157 for Linux. Users are advised to update their browsers as soon as possible.
Related: Chrome 138 Update Patches Zero-Day Vulnerability
Related: Chrome 138, Firefox 140 Patch Multiple Vulnerabilities
Related: Chrome 137 Update Patches High-Severity Vulnerabilities
Related: Chrome, Firefox Updates Resolve High-Severity Memory Bugs
Original Post URL: https://www.securityweek.com/chrome-update-patches-fifth-zero-day-of-2025/
Category & Tags: Vulnerabilities,Chrome,exploited,Zero-Day – Vulnerabilities,Chrome,exploited,Zero-Day
Views: 5