Apple has released urgent security updates to address a high-severity vulnerability that cybercriminals have actively exploited in zero-day attacks targeting Google Chrome users.
## The Vulnerability: CVE-2025-6558
The security flaw, designated CVE-2025-6558, stems from improper validation of untrusted input in ANGLE (Almost Native Graphics Layer Engine), an open-source graphics layer that processes GPU commands. This vulnerability allows remote attackers to execute malicious code within a browser’s GPU process through specially crafted web pages, potentially enabling them to break free from the browser’s security sandbox.
## Discovery and Timeline
Security researchers Vlad Stolyarov and Clément Lecigne from Google’s Threat Analysis Group (TAG) discovered the vulnerability in June. Google patched the flaw in Chrome on July 15, marking it as actively exploited. Google TAG specializes in defending against state-sponsored attacks and frequently uncovers zero-day exploits used by government-backed threat actors targeting high-risk individuals such as dissidents, journalists, and opposition politicians.
## Apple’s Response
On Tuesday, Apple released WebKit security updates addressing CVE-2025-6558 across multiple platforms:
– **iOS 18.6 and iPadOS 18.6**: iPhone XS and later models, various iPad Pro, Air, and mini generations
– **macOS Sequoia 15.6**: All compatible Mac computers
– **iPadOS 17.7.9**: Older iPad models including iPad Pro 12.9-inch 2nd generation
– **tvOS 18.6**: All Apple TV HD and Apple TV 4K models
– **visionOS 2.6**: Apple Vision Pro
– **watchOS 11.6**: Apple Watch Series 6 and later
Apple warns that successful exploitation could cause unexpected Safari crashes when processing malicious web content.
## Government Response
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its catalog of known exploited flaws on July 22, requiring federal agencies to patch their systems by August 12. CISA emphasized that such vulnerabilities pose significant risks and urged all organizations to prioritize patching immediately.
## Broader Security Context
This marks the sixth zero-day vulnerability Apple has patched in 2025, following five previous exploited flaws discovered throughout the year. The frequency of these attacks highlights the ongoing threat landscape facing Apple users and the importance of maintaining up-to-date software.
Organizations and individual users should install these security updates immediately to protect against potential exploitation of this critical vulnerability.
