CVE-2025-10585

9.5 CISA KEV

Google · Chromium V8

A type confusion vulnerability in the Google Chromium V8 engine allows a remote attacker to trigger heap corruption via a crafted HTML page.

Executive summary

A critical type confusion vulnerability in the Google Chromium V8 engine is currently being exploited in the wild, posing an immediate risk of remote code execution.

Vulnerability

The flaw exists due to type confusion within the V8 JavaScript engine, which can be triggered by an unauthenticated remote attacker using a specially crafted HTML page to achieve heap corruption.

Business impact

The vulnerability carries a CVSS score of 9.5, reflecting its potential for total system compromise, including arbitrary code execution and data exfiltration. Successful exploitation allows an attacker to bypass browser security boundaries, which could lead to significant data breaches, unauthorized system access, and potential lateral movement within the corporate environment.

Remediation

Immediate Action: Update Google Chrome to version 140.0.7339.185 or later immediately to incorporate the vendor provided security patches.

Proactive Monitoring: Monitor endpoint detection and response logs for unusual browser process behavior or unexpected child processes spawning from the Chrome application.

Compensating Controls: While browser updates are the primary defense, ensure that standard security baseline configurations are enforced to limit the impact of potential sandbox escapes.

Exploitation status

Public Exploit Available: Yes, two public proof-of-concept repositories have been identified on GitHub.

Analyst recommendation

Due to the confirmed active exploitation of this vulnerability in the wild, organizations must prioritize patching all instances of Google Chrome across their infrastructure. Given the critical nature of the flaw and the ease with which it can be triggered via malicious web content, delay in applying these updates significantly increases the risk of successful compromise.

More Google CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief kev section
  3. Published in the daily brief high section
  4. Published in the daily brief high section
  5. Published in the daily brief kev section
  6. Published in the daily brief kev section
  7. Published in the daily brief kev section
  8. Published in the daily brief kev section
  9. Published in the daily brief kev section
  10. Published in the daily brief kev section
  11. Published in the daily brief kev section
  12. Published in the daily brief kev section
  13. Published in the daily brief kev section
  14. Published in the daily brief kev section
  15. Published in the daily brief kev section
  16. Published in the daily brief kev section
  17. Published in the daily brief kev section
  18. Published in the daily brief kev section
  19. Published in the daily brief kev section
  20. Published in the daily brief kev section
  21. Published in the daily brief kev section
  22. Published in the daily brief kev section
  23. Look Back published
  24. Analyst report written
  25. Fix documented version 140.0.7339.185 per CVE record

Sources