CVE-2025-10585
KEVmassActively Exploited V8 Type Confusion in Google Chrome (Heap Corruption)
CISA: Google Chromium V8 Type Confusion Vulnerability
CVE-2025-10585 is a type confusion flaw (CWE-843) in the V8 JavaScript engine in Google Chrome and Chromium prior to version 140.0.7339.185. A remote attacker can trigger it via a crafted HTML page processed by the browser, causing V8 to mishandle object types and potentially exploit heap corruption, which can yield code execution in the browser. Any user or system running an affected Chrome/Chromium build is exposed, and Siemens Cadra is also listed as affected in the CPE data. The flaw is being actively exploited in the wild: Google patched it as a zero-day, CISA added it to the Known Exploited Vulnerabilities catalog on 2025-09-23, and reporting describes it as the sixth actively exploited Chrome zero-day of 2025.
What to do: Update Google Chrome to 140.0.7339.185 or later immediately (verify via Settings > About Chrome or through enterprise browser management); because the flaw is in CISA's KEV catalog, federal agencies must apply vendor mitigations per BOD 22-01 guidance or discontinue use if mitigations are unavailable. Organizations running products that embed Chromium, including Siemens Cadra per the CPE listing, should contact those vendors for patched builds. No public PoC is known, but in-the-wild exploitation is confirmed, so do not defer patching.
| Google Chrome | all versions prior to 140.0.7339.185 |
| Google Chromium (V8 engine) | Chromium-based builds prior to 140.0.7339.185 (per CISA affected list: Google Chromium V8) |
| Siemens Cadra | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- Affected
- Google Chromium V8
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown