CVE-2025-8010

8.8

Google · Chrome

A type confusion vulnerability in the V8 engine of Google Chrome allows remote attackers to trigger heap corruption via a crafted HTML page.

Executive summary

A critical type confusion vulnerability in the Google Chrome V8 engine could allow a remote attacker to execute arbitrary code or cause system crashes through a malicious webpage.

Vulnerability

This flaw is a type confusion vulnerability (CWE-843) located within the V8 JavaScript engine, which can be triggered by an unauthenticated remote attacker through a specifically crafted HTML page.

Business impact

The exploitation of this vulnerability can lead to heap corruption, potentially resulting in remote code execution or complete application failure. Given the CVSS score of 8.8, this poses a significant risk to organizational security, as it could facilitate unauthorized access to local user data or provide a pathway for further system compromise.

Remediation

Immediate Action: Update all Google Chrome installations to version 138.0.7204.168 or later immediately.

Proactive Monitoring: Review web filtering logs for users navigating to suspicious or untrusted domains that may attempt to deliver malicious HTML payloads.

Compensating Controls: Ensure that users are operating with the principle of least privilege to limit the potential impact of successful code execution within the browser process.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the severity of this heap corruption vulnerability, organizations should prioritize the deployment of the latest Chrome update across all endpoints. Failure to patch this flaw leaves systems exposed to remote exploitation, which could result in severe data loss or system compromise.

More Google CVEs

Sources