Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
2025-07-15T18:15:24.533
2025-11-06T14:52:01.530
Analyzed
CVSSv3.1: 8.8 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | chrome | < 138.0.7204.157 | Yes | |
| Operating System | debian | debian_linux | 11.0 | Yes |
| Application | apple | safari | < 18.6 | Yes |
| Operating System | apple | ipados | < 18.6 | Yes |
| Operating System | apple | iphone_os | < 18.6 | Yes |
| Operating System | apple | macos | < 15.6 | Yes |
| Operating System | apple | visionos | < 2.6 | Yes |
| Operating System | apple | watchos | < 11.6 | Yes |
| Application | wpewebkit | wpe_webkit | < 2.48.0 | Yes |
| Application | webkitgtk | webkitgtk | < 2.48.0 | Yes |