SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Google Chrome Zero-day Vulnerability Actively Exploited in the Wild

Google Chrome Zero-day Vulnerability Actively Exploited in the Wild

Google has urgently released a security update for its Chrome browser to address a zero-day vulnerability, CVE-2025-6558, which is currently being exploited in the wild. This update also includes patches for two additional high-severity flaws CVE-2025-7656 and CVE-2025-7657 making immediate action e...

Jul 15, 2025By Moulik Arora3 min read

Google has urgently released a security update for its Chrome browser to address a zero-day vulnerability, CVE-2025-6558, which is currently being exploited in the wild. This update also includes patches for two additional high-severity flaws CVE-2025-7656 and CVE-2025-7657 making immediate action essential to keep systems secure.

Vulnerability DetailsThe primary zero-day, CVE-2025-6558, stems from incorrect validation of untrusted input in the ANGLE (Almost Native Graphics Layer Engine) and GPU components. By crafting specially designed graphics calls, an attacker can trigger out-of-bounds memory access, potentially leading to arbitrary code execution.

In the same update, Google has fixed two other critical issues:

  • CVE-2025-7656: An integer overflow in the V8 JavaScript engine, which could allow attackers to execute arbitrary code by overflowing internal counters.
  • CVE-2025-7657: A use-after-free in the WebRTC functionality, enabling remote code execution or browser crashes when handling malformed media streams.

Root CauseThese vulnerabilities arise from distinct flaws within Chrome’s graphics and scripting subsystems:

  1. ANGLE/GPU input validation (CVE-2025-6558): Improper checks on user-supplied graphics data.
  2. V8 integer overflow (CVE-2025-7656): Lack of bounds checking on arithmetic operations in the JavaScript engine.
  3. WebRTC use-after-free (CVE-2025-7657): Failure to manage object lifetimes correctly during media negotiation.

Impact & Exploit Potential

  • CVE-2025-6558: Actively exploited in the wild, this flaw poses an immediate risk. Successful exploitation can lead to full browser compromise and potentially sandbox escape.
  • CVE-2025-7656: Integer overflows can corrupt memory or hijack control flow, often resulting in arbitrary code execution.
  • CVE-2025-7657: Use-after-free bugs may allow attackers to run malicious code or crash the browser, disrupting availability.

Unpatched users remain vulnerable to targeted attacks, drive-by downloads, and malicious web pages designed to exploit these flaws.

Affected Products

  • Windows & macOS: Chrome versions prior to 138.0.7204.157/.158
  • Linux: Chrome versions prior to 138.0.7204.157

Chromium-based browsers (Microsoft Edge, Brave, Opera, Vivaldi, etc.) are also likely affected and should be updated when vendor patches become available.

Mitigation & Recommendations

  1. Update Chrome Immediately: Navigate to Help > About Google Chrome to trigger the update to 138.0.7204.157/.158 (Windows/macOS) or 138.0.7204.157 (Linux).
  2. Exercise Caution: Avoid opening untrusted links or visiting unfamiliar websites until fully patched.
  3. Monitor Chromium-based Browsers: Apply vendor updates for other browsers as they roll out fixes.Explore more about the 3 CVEs mentioned above here

Instantly Fix Risks with Saner Patch ManagementSaner patch management is a continuous, automated solution that instantly addresses risks exploited in the wild. It supports Windows, Linux, macOS, and 550+ third-party applications.

  • Safe Testing Area: Validate patches in an isolated environment before deployment.
  • Patch Rollback: Revert updates seamlessly in case of failure or system issues.

Experience the fastest, most reliable patching software here.

Featured Posts

Open CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials
CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

CVE Research

CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

Two MikroTik RouterOS CVEs entered CISA KEV seven days after production fixes. Dated reporting places SSH-chain exploitation involving CVE-2026-86060 at least one calendar day before those releases; no comparable start date is established for CVE-2026-67277.

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch
Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

CVE Research

Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

Four vulnerabilities added to CISA’s KEV catalog on September 9, 2026 show widely different timelines between public disclosure and formal exploitation-based prioritization, ranging from one day to 239 days.

Sep 24, 2026

Open TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

CVE Research

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

A chronological look at how a long-running China-nexus espionage cluster evolved from server-side exploitation to a chained Chrome/Windows zero-day kit — and what that shift signals.

Sep 24, 2026