Junglewise Threat Intelligence

CVE-2025-10585: Google Chrome type confusion in V8 engine

CVE-2025-10585 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-09-24

Technologies: Google Chromium V8, Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Google, Apple, Microsoft, Siemens, Linux.

Executive brief

Google Chrome and related software using the V8 engine are vulnerable to a flaw that allows an attacker to corrupt the browser's memory. By tricking a user into visiting a specially crafted website, an attacker could potentially gain control over the user's system or access sensitive information. This vulnerability is particularly serious because it has been observed being used in active attacks in the wild.

Technical details

A type confusion vulnerability (CWE-843) exists in the V8 JavaScript and WebAssembly engine within Google Chrome. The flaw occurs when the engine incorrectly interprets the type of an object, leading to heap corruption. A remote, unauthenticated attacker can exploit this by hosting a malicious HTML page and enticing a user to visit it. Successful exploitation can lead to arbitrary code execution within the context of the browser renderer process. Google has confirmed that an exploit for this vulnerability exists in the wild, and CISA has added it to the Known Exploited Vulnerabilities (KEV) catalog. The issue is resolved in Chrome version 140.0.7339.185 and later.

Affected products

  • Google Chrome prior to 140.0.7339.185
  • Siemens CADRA All versions

Timeline

  • 2025-09-16: disclosed: Reported by Google Threat Analysis Group
  • 2025-09-17: patched: Chrome Stable Channel Update released
  • 2025-09-23: kev added: Added to CISA KEV catalog due to active exploitation
  • 2025-09-24: advisory: NVD publication date

References

Related threats