ZeroHour

CVE-2025-13223

KEVmass

Actively Exploited V8 Type Confusion in Google Chrome and Siemens Chromium Components

CISA: Google Chromium V8 Type Confusion Vulnerability

CVSS 3.1
8.8 high
EPSS
5%p92
Published
()
KEV added
AI analysis

CVE-2025-13223 is a type confusion (CWE-843) in the V8 JavaScript engine of Google Chromium, rated High severity by Chromium. A remote attacker can trigger it by luring a user to a crafted HTML page; because browsing is interactive, successful exploitation requires user action (AV:N/PR:N/UI:R). If exploited, the type confusion can lead to heap corruption, which typically enables arbitrary code execution or sandbox-escape-capable memory corruption in the renderer. Anyone running Google Chrome prior to 142.0.7444.175 is affected, and CISA's CPE data also lists Siemens CADRA as an affected product, consistent with Siemens shipping Chromium-based components; CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-11-19. The headlines indicate this is the seventh Chrome zero-day of the year and that it was patched by Google after being observed under active exploitation in the wild; no public proof-of-concept is cataloged, EPSS puts 30-day exploitation probability at 5.0% (92nd percentile), and ransomware association is unknown.

What to do: Update Google Chrome to 142.0.7444.175 or later on all endpoints, including managed fleets and kiosk deployments, and verify the patched version in chrome://version. Because the flaw is on the CISA KEV list (added 2025-11-19), federal agencies must apply vendor mitigations or follow BOD 22-01 guidance by the required deadline. Organizations running Siemens CADRA or other Siemens products embedding Chromium V8 should check Siemens productCERT advisories for affected versions and updated builds, and prioritize patching internet-facing or user-workstation contexts where untrusted web content is rendered.

Affected
Google Chrome (Chromium V8)prior to 142.0.7444.175
Siemens CADRA (Chromium-based component, per CISA CPE data)
Estimated exposure
massbillions of Chrome installations worldwide (Chrome has an estimated 3+ billion users), with Siemens CADRA deployments adding an unquantified industrial niche — Chrome's installed base is measured in billions per public browser market-share data, though auto-updating limits the actively vulnerable subset to users on versions before 142.0.7444.175; the Siemens CADRA install base has no public…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CISA Known Exploited Vulnerability
Affected
Google Chromium V8
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
googlesiemens
Products
chrome, cadra
Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news