logo

Apple patches security flaw exploited in Chrome zero-day attacks

ID: 8cc74a66-0ea7-58e8-94b9-a2dbb879c704

STIX ID: report--8cc74a66-0ea7-58e8-94b9-a2dbb879c704

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-07-30

Date Updated: 2026-07-17

Author: Sergiu Gatlan

...
...

Apple and Google addressed a high-severity zero-day (CVE-2025-6558) in the ANGLE graphics layer that allows remote code execution in the browser GPU process and may enable sandbox escape; Google TAG discovered the flaw, Google patched Chrome on July 15 noting active exploitation, and Apple released WebKit updates across iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. CISA added the vulnerability to its catalog of known-exploited vulnerabilities and set a remediation deadline for federal agencies, while Apple also disclosed several other zero-days patched earlier in the year.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.