Executive brief
Google Chrome is a widely used web browser, and the V8 component is the engine responsible for executing JavaScript. A security flaw has been identified that allows a remote attacker to corrupt the browser's memory when a user visits a specially crafted website. This could lead to the theft of sensitive information, unauthorized access to user accounts, or the execution of malicious code on the victim's computer. Google has confirmed that this vulnerability is being actively exploited in the wild.
Technical details
A type confusion vulnerability (CWE-843) exists in the V8 JavaScript engine within Google Chrome. The flaw is triggered when the engine incorrectly handles object types during execution, leading to heap corruption. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious HTML page. Successful exploitation can result in arbitrary code execution within the browser's sandbox or a process crash. Google has acknowledged active exploitation (zero-day) of this flaw. The issue is resolved in Chrome version 142.0.7444.175 and later. Siemens CADRA is also noted as affected due to its reliance on vulnerable components.
Affected products
- Google Chrome prior to 142.0.7444.175
- Siemens CADRA All versions
Timeline
- 2025-11-12: disclosed: Reported by Google Threat Analysis Group
- 2025-11-17: patched: Chrome version 142.0.7444.175 released
- 2025-11-17: advisory: Initial Google Chrome security advisory published
- 2025-11-17: exploited: Google confirmed exploit exists in the wild
- 2025-11-19: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2026-07-14: advisory: Siemens published advisory SSA-470355 regarding CADRA impact