07/18/2025
Threat Notice: Multiple Vulnerabilities in Google Chrome
Vulnerability Information
Google released patches for six vulnerabilities impacting the Chrome web browser, including one that has been actively exploited. The vulnerabilities include:
CVE-2025-7656: an integer overflow in V8 in Google Chrome prior to 138.0.7204.157
CVE-2025-7657: a use-after-free in WebRTC in Google Chrome prior to 138.0.7204.157
CVE-2025-6558 (CVSS 8.😎 is an actively exploited vulnerability described as an incorrect validation of untrusted input in the browser's ANGLE and GPU components.
How can this be used maliciously?
ANGLE (Almost Native Graphics Layer Engine) acts as a translation layer between Chrome’s rendering engine and device-specific graphics drivers. Vulnerabilities impacting this module can allow threat actors to escape Chrome’s sandbox by abusing low-level GPU operations. A sandbox escape could allow a threat actor to interact with the underlying system, effectively compromising the overall system.
Is there active exploitation at the time of writing?
At the time of writing (July 16, 2025), Google acknowledged that there is an exploit available in the wild for CVE-2025-6558 and that it has been actively exploited. According to the NVD entry, remote attackers exploited the vulnerability to perform a sandbox escape via a crafted HTML page.
We at CBT make sure apps like Chrome are always up to date, ensuring these critical patches are pushed out.
This alert came from our advanced security team where we offer 24/7 monitoring by real humans. For more information on this, give us a call or send us a message!