U.S. CISA adds Google Chromium flaw to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-10585 | Actively Exploited V8 Type Confusion in Google Chrome (Heap Corruption) CVE-2025-10585 is a type confusion flaw (CWE-843) in the V8 JavaScript engine in Google Chrome and Chromium prior to version 140.0.7339.185. A remote attacker can trigger it via a crafted HTML page processed by the browser, causing V8 to mishandle object types and potentially exploit heap corruption, which can yield code execution in the browser. Any user or system running an affected Chrome/Chromium build is exposed, and Siemens Cadra is also listed as affected in the CPE data. The flaw is being actively exploited in the wild: Google patched it as a zero-day, CISA added it to the Known Exploited Vulnerabilities catalog on 2025-09-23, and reporting describes it as the sixth actively exploited Chrome zero-day of 2025. Do: Update Google Chrome to 140.0.7339.185 or later immediately (verify via Settings > About Chrome or through enterprise browser management); because the flaw is in CISA's KEV catalog, federal agencies must apply vendor mitigations per BOD 22-01 guidance or discontinue use if mitigations are unavailable. Organizations running products that embed Chromium, including Siemens Cadra per the CPE listing, should contact those vendors for patched builds. No public PoC is known, but in-the-wild exploitation is confirmed, so do not defer patching. | 9.8 | 5% | KEV |
| mass≈3+ billion Chrome users/installations worldwide, plus an unknown number of Chromium-embedded deployments (e.g., Siemens Cadra) |
Full article372 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
September 23, 2025

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium flaw to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Google Chromium flaw, tracked as CVE-2025-10585, to its Known Exploited Vulnerabilities (KEV) catalog.
In mid-September, Google released security updates to address four vulnerabilities in the Chrome web browser, including CVE-2025-10585, which has reportedly been exploited in the wild.
“Google is aware that an exploit for CVE-2025-10585 exists in the wild.” reads the advisory published by Google.
The zero-day vulnerability CVE-2025-10585 is a type confusion issue in the V8 JavaScript and WebAssembly engine.
A type confusion issue happens when software misinterprets a piece of memory as the wrong type of object. This confusion can let attackers corrupt memory, crash the program, or execute malicious code. It’s common in C/C++ apps like browsers, where weak memory safety makes such exploits possible.
Google’s Threat Analysis Group (TAG) discovered the vulnerability CVE-2025-10585 on September 16, 2025. Google did not share technical details about the attacks exploiting this vulnerability.
Google’s TAG team investigates attacks by nation-state actors and commercial spyware vendors. One of these threat actors likely exploited the issue in the wild.
CVE-2025-10585 is the sixth Chrome zero-day vulnerability that has been actively exploited in the wild in 2025.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the vulnerabilities by October 2, 2025.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the vulnerabilities by October 14, 2025.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/182509/security/u-s-cisa-adds-google-chromium-flaw-to-its-known-exploited-vulnerabilities-catalog.html