ZeroHour

CVE-2025-10585

KEVmass

Actively Exploited V8 Type Confusion in Google Chrome (Heap Corruption)

CISA: Google Chromium V8 Type Confusion Vulnerability

CVSS 3.1
9.8 critical
EPSS
5%p92
Published
()
KEV added
AI analysis

CVE-2025-10585 is a type confusion flaw (CWE-843) in the V8 JavaScript engine in Google Chrome and Chromium prior to version 140.0.7339.185. A remote attacker can trigger it via a crafted HTML page processed by the browser, causing V8 to mishandle object types and potentially exploit heap corruption, which can yield code execution in the browser. Any user or system running an affected Chrome/Chromium build is exposed, and Siemens Cadra is also listed as affected in the CPE data. The flaw is being actively exploited in the wild: Google patched it as a zero-day, CISA added it to the Known Exploited Vulnerabilities catalog on 2025-09-23, and reporting describes it as the sixth actively exploited Chrome zero-day of 2025.

What to do: Update Google Chrome to 140.0.7339.185 or later immediately (verify via Settings > About Chrome or through enterprise browser management); because the flaw is in CISA's KEV catalog, federal agencies must apply vendor mitigations per BOD 22-01 guidance or discontinue use if mitigations are unavailable. Organizations running products that embed Chromium, including Siemens Cadra per the CPE listing, should contact those vendors for patched builds. No public PoC is known, but in-the-wild exploitation is confirmed, so do not defer patching.

Affected
Google Chromeall versions prior to 140.0.7339.185
Google Chromium (V8 engine)Chromium-based builds prior to 140.0.7339.185 (per CISA affected list: Google Chromium V8)
Siemens Cadra
Estimated exposure
mass≈3+ billion Chrome users/installations worldwide, plus an unknown number of Chromium-embedded deployments (e.g., Siemens Cadra) — Chrome is the world's dominant browser (roughly 65% desktop market share) with an install base exceeding 3 billion users, and the affected scope covers the Chromium V8 engine broadly, so this is clearly mass-scale; the Siemens Cadra…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CISA Known Exploited Vulnerability
Affected
Google Chromium V8
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
googlesiemens
Products
chrome, cadra
Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news