Google patches yet another exploited Chrome zero-day (CVE-2025-13223)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-13223 | Actively Exploited V8 Type Confusion in Google Chrome and Siemens Chromium Components CVE-2025-13223 is a type confusion (CWE-843) in the V8 JavaScript engine of Google Chromium, rated High severity by Chromium. A remote attacker can trigger it by luring a user to a crafted HTML page; because browsing is interactive, successful exploitation requires user action (AV:N/PR:N/UI:R). If exploited, the type confusion can lead to heap corruption, which typically enables arbitrary code execution or sandbox-escape-capable memory corruption in the renderer. Anyone running Google Chrome prior to 142.0.7444.175 is affected, and CISA's CPE data also lists Siemens CADRA as an affected product, consistent with Siemens shipping Chromium-based components; CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-11-19. The headlines indicate this is the seventh Chrome zero-day of the year and that it was patched by Google after being observed under active exploitation in the wild; no public proof-of-concept is cataloged, EPSS puts 30-day exploitation probability at 5.0% (92nd percentile), and ransomware association is unknown. Do: Update Google Chrome to 142.0.7444.175 or later on all endpoints, including managed fleets and kiosk deployments, and verify the patched version in chrome://version. Because the flaw is on the CISA KEV list (added 2025-11-19), federal agencies must apply vendor mitigations or follow BOD 22-01 guidance by the required deadline. Organizations running Siemens CADRA or other Siemens products embedding Chromium V8 should check Siemens productCERT advisories for affected versions and updated builds, and prioritize patching internet-facing or user-workstation contexts where untrusted web content is rendered. | 8.8 | 5% | KEV |
| massbillions of Chrome installations worldwide (Chrome has an estimated 3+ billion users), with Siemens CADRA deployments adding an unquantified industrial niche | |
| CVE-2025-13224 | Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) NVD description · AI analysis pending | 8.8 | <1% |
| — |
Full article256 words · extracted from helpnetsecurity.com · click to collapse
Google has shipped an emergency fix for a Chrome vulnerability (CVE-2025-13223) reported as actively exploited in the wild by its Threat Analysis Group (TAG).
About CVE-2025-13223
CVE-2025-13223 is a type confusion vulnerability in V8, the JavaScript and WebAssembly engine used by Chrome and Chromium-based browsers.
The flaw allows remote attackers to exploit heap corruption via a specially crafted HTML page, and can lead to unauthorized actions such as accessing sensitive data. For the exploit to have a chance to work, targets must be tricked into visiting such a page.
CVE-2025-13223 and a second V8 type-confusion flaw, CVE-2025-13224, have been fixed in Chrome:
- v142.0.7444.175/.176 (for Windows)
- v142.0.7444.176 (for macOS)
- v142.0.7444.175 (for Linux)
CVE-2025-13223 was reported by Clément Lecigne of Google TAG, and CVE-2025-13224 was discovered by Big Sleep, Google’s autonomous AI-powered system for automated vulnerability research.
Zero-days affecting V8 are often exploited by attackers: in 2025 alone, Google fixed several of them after TAG researchers flagged related abuse.
Updates are available/incoming
Google says that the fixed Chrome versions will roll out over the coming days/weeks.
The browser is updated automatically once updates become available, but you can also manually trigger the update to a fixed version (go to Settings -> About Chrome) and then relaunch the application to finalize the upgrade.
Chromium-based browsers like Microsoft Edge, Brave, and Opera are expected to get these fixes soon, and Vivaldi maintainers have already delivered a fix for CVE-2025-13223.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/11/18/chrome-cve-2025-13223-exploited/