ZeroHour

CVE-2025-6554

KEVmass

Type Confusion in Google Chrome V8 Allows Arbitrary Read/Write (Actively Exploited)

CISA: Google Chromium V8 Type Confusion Vulnerability

CVSS 3.1
8.1 high
EPSS
13%p96
Published
()
KEV added
AI analysis

CVE-2025-6554 is a type confusion vulnerability (CWE-843) in the V8 JavaScript engine of Google Chrome, affecting versions prior to 138.0.7204.96. A remote attacker can trigger it by inducing a user to open a crafted HTML page, and the flaw permits arbitrary read and write within the browser renderer process. Successful exploitation yields high confidentiality and integrity impact, and V8 type confusion bugs are commonly used as the first stage toward a full browser compromise. Any user of an unpatched Chrome or Chromium-based browser is exposed, and the flaw is being actively exploited in the wild as a zero-day; CISA added it to the Known Exploited Vulnerabilities catalog on 2025-07-02. Ransomware usage is not confirmed (reported as unknown), and no public proof-of-concept is known.

What to do: Update Chrome to 138.0.7204.96 or later (check chrome://settings/help) and restart the browser to load the patched V8; users of Chromium-derived browsers (Edge, Brave, Opera, etc.) should install their vendor's corresponding V8 patch. Organizations must apply vendor mitigations or follow BOD 22-01 guidance given the KEV listing, and should inventory managed browsers and force-update policies to confirm rollout.

Affected
Google Chromeall versions prior to 138.0.7204.96
Google Chromium V8 JavaScript engineV8 versions shipping in Chromium/Chrome prior to the 138.0.7204.96 fix
Estimated exposure
mass≈3+ billion Chrome users; effectively every desktop Chrome installation running a build older than 138.0.7204.96 — Chrome holds roughly two-thirds of global browser usage share with an installed base commonly estimated at 3+ billion users, essentially all of whom ran an affected V8 build before applying the 138.0.7204.96 fix.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

CISA Known Exploited Vulnerability
Affected
Google Chromium V8
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
google
Products
chrome
Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

In the news