CVE-2025-13223

9.5 CISA KEV

Google · Chrome

A type confusion vulnerability in the V8 engine of Google Chrome allows a remote attacker to achieve heap corruption via a crafted HTML page.

Executive summary

A critical type confusion vulnerability in the Google Chrome V8 engine is currently being exploited in the wild, posing a severe risk of remote code execution.

Vulnerability

This is a type confusion flaw within the V8 JavaScript engine. An unauthenticated remote attacker can trigger heap corruption by enticing a user to visit a specially crafted HTML page.

Business impact

The ability to trigger heap corruption remotely presents a significant threat to organizational security. Successful exploitation could lead to arbitrary code execution, potentially resulting in complete system compromise, data theft, or the installation of malicious software. Given the CVSS score of 9.5 and the confirmation of active exploitation in the wild, this vulnerability represents an immediate and critical risk to business operations.

Remediation

Immediate Action: Update all instances of Google Chrome to version 142.0.7444.175 or later immediately.

Proactive Monitoring: Monitor network traffic for unusual browser behavior and review endpoint security logs for signs of anomalous process execution originating from browser sessions.

Compensating Controls: While no direct virtual patch exists, deploying robust endpoint detection and response (EDR) solutions and ensuring browser sandboxing features remain enabled can help limit the impact of potential exploits.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the critical severity and confirmed active exploitation of this vulnerability, organizations must prioritize the immediate deployment of the patched version of Google Chrome across all endpoints. Delaying this update exposes the enterprise to a high probability of compromise by sophisticated adversaries currently leveraging this flaw.

More Google CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section
  3. Published in the daily brief kev section
  4. Published in the daily brief kev section
  5. Published in the daily brief kev section
  6. Published in the daily brief kev section
  7. Published in the daily brief kev section
  8. Published in the daily brief kev section
  9. Published in the daily brief kev section
  10. Published in the daily brief kev section
  11. Published in the daily brief kev section
  12. Published in the daily brief kev section
  13. Published in the daily brief kev section
  14. Published in the daily brief kev section
  15. Published in the daily brief kev section
  16. Published in the daily brief kev section
  17. Published in the daily brief critical section
  18. Published in the daily brief critical section
  19. Published in the daily brief critical section
  20. Published in the daily brief kev section
  21. Published in the daily brief kev section
  22. Published in the daily brief kev section
  23. Analyst report written
  24. Fix documented version 142.0.7444.175 per CVE record

Sources