CVE-2025-13223
9.5 CISA KEVGoogle · Chrome
A type confusion vulnerability in the V8 engine of Google Chrome allows a remote attacker to achieve heap corruption via a crafted HTML page.
Executive summary
A critical type confusion vulnerability in the Google Chrome V8 engine is currently being exploited in the wild, posing a severe risk of remote code execution.
Vulnerability
This is a type confusion flaw within the V8 JavaScript engine. An unauthenticated remote attacker can trigger heap corruption by enticing a user to visit a specially crafted HTML page.
Business impact
The ability to trigger heap corruption remotely presents a significant threat to organizational security. Successful exploitation could lead to arbitrary code execution, potentially resulting in complete system compromise, data theft, or the installation of malicious software. Given the CVSS score of 9.5 and the confirmation of active exploitation in the wild, this vulnerability represents an immediate and critical risk to business operations.
Remediation
Immediate Action: Update all instances of Google Chrome to version 142.0.7444.175 or later immediately.
Proactive Monitoring: Monitor network traffic for unusual browser behavior and review endpoint security logs for signs of anomalous process execution originating from browser sessions.
Compensating Controls: While no direct virtual patch exists, deploying robust endpoint detection and response (EDR) solutions and ensuring browser sandboxing features remain enabled can help limit the impact of potential exploits.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the critical severity and confirmed active exploitation of this vulnerability, organizations must prioritize the immediate deployment of the patched version of Google Chrome across all endpoints. Delaying this update exposes the enterprise to a high probability of compromise by sophisticated adversaries currently leveraging this flaw.
More Google CVEs all →
History
- Disclosed CVE record published
- Published in the daily brief high section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief critical section
- Published in the daily brief critical section
- Published in the daily brief critical section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Analyst report written
- Fix documented version 142.0.7444.175 per CVE record