CVE-2025-13230

8.8

Google · Chrome

A type confusion vulnerability in the V8 engine of Google Chrome allows remote attackers to trigger heap corruption via a crafted HTML page.

Executive summary

A high-severity type confusion vulnerability in Google Chrome allows remote attackers to cause heap corruption, potentially leading to arbitrary code execution.

Vulnerability

This is a type confusion vulnerability (CWE-843) within the V8 JavaScript engine. An unauthenticated remote attacker can trigger this flaw by enticing a user to visit a malicious website, leading to heap corruption.

Business impact

Successful exploitation of this vulnerability can result in full system compromise, as it allows for arbitrary code execution within the context of the browser. Given the CVSS score of 8.8, this poses a significant risk to organizational data integrity and confidentiality, potentially allowing attackers to bypass security controls and gain unauthorized access to the underlying host system.

Remediation

Immediate Action: Update all Google Chrome installations to version 142.0.7444.59 or later immediately.

Proactive Monitoring: Monitor browser-based traffic for suspicious patterns or anomalous redirects to unknown domains, and audit endpoint logs for unexpected process execution originating from the browser.

Compensating Controls: Utilize enterprise browser management policies to restrict the execution of untrusted scripts and ensure that security features like site isolation are strictly enforced across all managed endpoints.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this vulnerability necessitates an immediate organization-wide update to the latest version of Google Chrome. Security teams should treat this as a high-priority deployment to prevent potential remote code execution attacks targeting browser users.

More Google CVEs

Sources