Hello all,

On Tue, 29 Sep 2026 02:18:45 +0200 Adrian Perez de Castro <[email protected]> 
wrote:
> ------------------------------------------------------------------------
> WebKitGTK and WPE WebKit Security Advisory                 WSA-2026-0006
> ------------------------------------------------------------------------
> 
> [...]
>     
> CVE-2025-6558
>     Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
>     earlier.
>     Insufficient validation of untrusted input in ANGLE and GPU in
>     Google Chrome prior to 138.0.7204.157 allowed a remote attacker to
>     potentially perform a sandbox escape via a crafted HTML page.
>     (Chromium security severity: High).
>
> [...]

CVE-2025-6558 had been already reported as fixed in version WebKitGTK 2.48.5
and WPE WebKit 2.48.5, as per WSA-2025-0005 [1].

Sorry about the inconvenience this mistake might have caused.

Cheers,
—Adrián

---
[1] https://webkitgtk.org/security/WSA-2025-0005.html#CVE-2025-6558

Attachment: signature.asc
Description: PGP signature

Reply via email to