ZeroHour
Security Affairspublished ()ingested @securityaffairs

Google fixed the seventh Chrome zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-10585
Actively Exploited V8 Type Confusion in Google Chrome (Heap Corruption)

CVE-2025-10585 is a type confusion flaw (CWE-843) in the V8 JavaScript engine in Google Chrome and Chromium prior to version 140.0.7339.185. A remote attacker can trigger it via a crafted HTML page processed by the browser, causing V8 to mishandle object types and potentially exploit heap corruption, which can yield code execution in the browser. Any user or system running an affected Chrome/Chromium build is exposed, and Siemens Cadra is also listed as affected in the CPE data. The flaw is being actively exploited in the wild: Google patched it as a zero-day, CISA added it to the Known Exploited Vulnerabilities catalog on 2025-09-23, and reporting describes it as the sixth actively exploited Chrome zero-day of 2025.

Do: Update Google Chrome to 140.0.7339.185 or later immediately (verify via Settings > About Chrome or through enterprise browser management); because the flaw is in CISA's KEV catalog, federal agencies must apply vendor mitigations per BOD 22-01 guidance or discontinue use if mitigations are unavailable. Organizations running products that embed Chromium, including Siemens Cadra per the CPE listing, should contact those vendors for patched builds. No public PoC is known, but in-the-wild exploitation is confirmed, so do not defer patching.

9.85% KEV
  • Google Chrome all versions prior to 140.0.7339.185
  • Google Chromium (V8 engine) Chromium-based builds prior to 140.0.7339.185 (per CISA affected list: Google Chromium V8)
  • Siemens Cadra
mass≈3+ billion Chrome users/installations worldwide, plus an unknown number of Chromium-embedded deployments (e.g., Siemens Cadra)
CVE-2025-13223
Actively Exploited V8 Type Confusion in Google Chrome and Siemens Chromium Components

CVE-2025-13223 is a type confusion (CWE-843) in the V8 JavaScript engine of Google Chromium, rated High severity by Chromium. A remote attacker can trigger it by luring a user to a crafted HTML page; because browsing is interactive, successful exploitation requires user action (AV:N/PR:N/UI:R). If exploited, the type confusion can lead to heap corruption, which typically enables arbitrary code execution or sandbox-escape-capable memory corruption in the renderer. Anyone running Google Chrome prior to 142.0.7444.175 is affected, and CISA's CPE data also lists Siemens CADRA as an affected product, consistent with Siemens shipping Chromium-based components; CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-11-19. The headlines indicate this is the seventh Chrome zero-day of the year and that it was patched by Google after being observed under active exploitation in the wild; no public proof-of-concept is cataloged, EPSS puts 30-day exploitation probability at 5.0% (92nd percentile), and ransomware association is unknown.

Do: Update Google Chrome to 142.0.7444.175 or later on all endpoints, including managed fleets and kiosk deployments, and verify the patched version in chrome://version. Because the flaw is on the CISA KEV list (added 2025-11-19), federal agencies must apply vendor mitigations or follow BOD 22-01 guidance by the required deadline. Organizations running Siemens CADRA or other Siemens products embedding Chromium V8 should check Siemens productCERT advisories for affected versions and updated builds, and prioritize patching internet-facing or user-workstation contexts where untrusted web content is rendered.

8.85% KEV
  • Google Chrome (Chromium V8) prior to 142.0.7444.175
  • Siemens CADRA (Chromium-based component, per CISA CPE data)
massbillions of Chrome installations worldwide (Chrome has an estimated 3+ billion users), with Siemens CADRA deployments adding an unquantified industrial niche
CVE-2025-13224
Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

NVD description · AI analysis pending
8.8<1%
  • google chrome
CVE-2025-2783
Sandbox Escape via Mojo Handle Flaw in Google Chrome on Windows (CVE-2025-2783)

CVE-2025-2783 is a high-severity sandbox escape in Google Chrome on Windows, caused by an incorrect handle being provided in unspecified circumstances in Mojo, Chrome's inter-process communication layer. It is triggered remotely through a malicious file and requires user interaction; an attacker who has code running inside Chrome's sandboxed renderer can abuse the handle flaw to break out of the Windows sandbox and gain broader access to the host (CVSS scope change with high impact to confidentiality, integrity, and availability). All Google Chrome versions on Windows prior to 134.0.6998.177 are affected, per the vendor fix referenced by CISA. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-27, and related reporting links it to active exploitation in the ForumTroll APT's phishing campaign against Russian scholars using fake eLibrary emails; ransomware use is unknown. No public proof-of-concept is known, and EPSS assigns a 9.2% probability of exploitation within 30 days (95th percentile).

Do: Update Google Chrome on Windows to 134.0.6998.177 or later immediately and verify deployed browser versions across endpoints; the flaw is in the CISA KEV catalog, so federal agencies must apply vendor mitigations per BOD 22-01 timelines. Because exploitation is tied to malicious files delivered via phishing (e.g., the ForumTroll fake-eLibrary campaign), prioritize patching for users who open untrusted attachments and links, and hunt for associated phishing emails.

8.39% KEV
  • Google Chrome Windows versions prior to 134.0.6998.177
  • Google Chromium (Mojo IPC component) Windows builds prior to the 134.0.6998.177 fix, as listed by CISA (affected component: Google Chromium Mojo)
massbillions of users (Chrome is the world's dominant browser; the Windows-only subset is still likely well over 1 billion)
CVE-2025-4664
Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

NVD description · AI analysis pending
4.36%
  • google chrome
CVE-2025-5419
Actively Exploited Out-of-Bounds Read/Write in Chromium V8 (Chrome, Edge)

CVE-2025-5419 is an out-of-bounds read and write (CWE-125, CWE-787) in the V8 JavaScript engine used by Google Chromium, rated High with a CVSS 3.1 score of 8.8. A remote attacker can trigger it by persuading a user to open a crafted HTML page (network attack vector, user interaction required, no privileges needed). Successful exploitation can corrupt the V8 heap, potentially giving the attacker code execution in the context of the browser with high impact on confidentiality, integrity, and availability. Anyone running the unpatched V8 engine is affected, including Google Chrome prior to 137.0.7151.68 and Chromium-based browsers such as Microsoft Edge that ship the vulnerable engine. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-06-05, though ransomware use is not yet known.

Do: Update Google Chrome to 137.0.7151.68 or later and restart the browser to load the fixed V8 (verify the version at chrome://version); apply the corresponding Chromium 137-based security update for Microsoft Edge and confirm via edge://version. Federal agencies must apply vendor mitigations or follow BOD 22-01 cloud-service guidance per the KEV listing. Since exploitation occurs via attacker-crafted web pages, prompt patching is the primary mitigation, and no public PoC is currently known.

8.88% KEV
  • Google Chrome (V8 JavaScript engine) prior to 137.0.7151.68
  • Google Chromium V8 (component per CISA) V8 as shipped in Chrome prior to 137.0.7151.68
  • Microsoft Edge (Chromium-based) builds incorporating the unpatched V8 engine; fixed version number not stated in source data
masson the order of billions of browser users were exposed pre-patch (Chrome alone ~3B+ users at ~65% global browser share, plus hundreds of millions of Edge users)
CVE-2025-6554
Type Confusion in Google Chrome V8 Allows Arbitrary Read/Write (Actively Exploited)

CVE-2025-6554 is a type confusion vulnerability (CWE-843) in the V8 JavaScript engine of Google Chrome, affecting versions prior to 138.0.7204.96. A remote attacker can trigger it by inducing a user to open a crafted HTML page, and the flaw permits arbitrary read and write within the browser renderer process. Successful exploitation yields high confidentiality and integrity impact, and V8 type confusion bugs are commonly used as the first stage toward a full browser compromise. Any user of an unpatched Chrome or Chromium-based browser is exposed, and the flaw is being actively exploited in the wild as a zero-day; CISA added it to the Known Exploited Vulnerabilities catalog on 2025-07-02. Ransomware usage is not confirmed (reported as unknown), and no public proof-of-concept is known.

Do: Update Chrome to 138.0.7204.96 or later (check chrome://settings/help) and restart the browser to load the patched V8; users of Chromium-derived browsers (Edge, Brave, Opera, etc.) should install their vendor's corresponding V8 patch. Organizations must apply vendor mitigations or follow BOD 22-01 guidance given the KEV listing, and should inventory managed browsers and force-update policies to confirm rollout.

8.113% KEV
  • Google Chrome all versions prior to 138.0.7204.96
  • Google Chromium V8 JavaScript engine V8 versions shipping in Chromium/Chrome prior to the 138.0.7204.96 fix
mass≈3+ billion Chrome users; effectively every desktop Chrome installation running a build older than 138.0.7204.96
CVE-2025-6558
Actively Exploited Input Validation Flaw in Chrome ANGLE/GPU Allows Sandbox Escape

CVE-2025-6558 is an improper input validation flaw (CWE-20) in the ANGLE graphics translation layer and GPU processing code of Google Chrome/Chromium prior to version 138.0.7204.157. A remote attacker can trigger it by convincing a user to open a crafted HTML page (user interaction is required), and successful exploitation potentially enables a sandbox escape from the browser's renderer with high impact on confidentiality, integrity, and availability. Per the CPE data, exposure extends beyond Chrome to Debian's Chromium package, Apple Safari and its operating systems (iOS, iPadOS, macOS, visionOS, watchOS), and the WebKitGTK and WPE WebKit ports, consistent with the shared ANGLE/WebKit code. Google fixed the issue in Chrome 138.0.7204.157, and CISA added the flaw to the KEV catalog on 2025-07-22, confirming active exploitation in the wild (ransomware use: unknown). EPSS assigns a 9.6% probability of exploitation within 30 days (95th percentile); no public proof-of-concept is known.

Do: Upgrade Google Chrome/Chromium to 138.0.7204.157 or later immediately, as the flaw is being actively exploited and is KEV-listed. Debian users should install the distribution's patched Chromium package, and operators of Apple platforms, WebKitGTK, or WPE WebKit deployments should apply the corresponding vendor security updates. Federal agencies must apply vendor mitigations per BOD 22-01 within the required timeframe or discontinue use if mitigations are unavailable.

8.810% KEV
  • Google Chrome prior to 138.0.7204.157
  • Google Chromium prior to 138.0.7204.157
  • Debian Linux (Chromium package)
  • +8 more
massbillions of users/installations (Chrome and Chromium-derived browsers)
Full article545 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini November 18, 2025

Google patched two Chrome flaws, including a V8 type-confusion bug, tracked as including CVE-2025-13223, which was exploited in the wild.

Google released Chrome security updates to address two flaws, including a high-severity V8 type confusion bug tracked as CVE-2025-13223 that has been actively exploited in the wild.

The Chrome V8 engine is Google’s open-source JavaScript and WebAssembly engine, written in C++, that executes code for browsers like Google Chrome and applications like Node.js.

A type confusion issue happens when software misinterprets a piece of memory as the wrong type of object. This confusion can let attackers corrupt memory, crash the program, or execute malicious code. It’s common in C/C++ apps like browsers, where weak memory safety makes such exploits possible.

An attacker can trigger the vulnerability via a crafted HTML page to achieve code execution or lead to crashes.

The flaw impacts the V8 script engine in Google Chrome before 142.0.7444.175.

“Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)” reads the NIST’s advisory.

“Google is aware that an exploit for CVE-2025-13223 exists in the wild.” reads the advisory.

Clément Lecigne of Google’s Threat Analysis Group (TAG) reported the vulnerability on November 12, 2025. Google’s TAG team investigates attacks by nation-state actors and commercial spyware vendors. One of these threat actors likely exploited the issue in the wild. As usual, Google has not shared any details on the attacks exploiting this vulnerability.

The IT giant also addressed the vulnerability CVE-2025-13224, which is a Type Confusion in V8. Google discovered the vulnerability using its Big Sleep on October 9, 2025.

Users should update Chrome to version 142.0.7444.175/.176, depending on their OS and relaunch to apply fixes.

CVE-2025-13223 is the seventh Chrome zero-day vulnerability that has been actively exploited in the wild in 2025. The other zero-day flaws addressed by Google this year are:

  • CVE-2025-10585 – The vulnerability is a type confusion issue in the V8 JavaScript and WebAssembly engine.
  • CVE-2025-6558 – The vulnerability is an insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 that can allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
  • CVE-2025-5419 – The vulnerability is an out-of-bounds read and write in the V8 JavaScript engine in Google Chrome prior. An attacker can exploit the flaw to trigger a heap corruption via a crafted HTML page. The flaw is actively exploited in the wild.
  • CVE-2025-4664 – The vulnerability is a Chrome browser vulnerability that could lead to full account takeover. Google is aware that an exploit for CVE-2025-5419 exists in the wild.
  • CVE-2025-2783 – The vulnerability is an incorrect handle provided in unspecified circumstances in Mojo on Windows. Kaspersky researchers Boris Larin (@oct0xor) and Igor Kuznetsov (@2igosha) reported the vulnerability on March 20, 2025. Google released out-of-band fixes to address the high-severity security vulnerability in the Chrome browser for Windows. The flaw was actively exploited in attacks targeting organizations in Russia.
  • CVE-2025-6554 – The vulnerability is a type-confusing issue that resides in the V8 JavaScript and WebAssembly engine.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, zero-day)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/184764/hacking/google-fixed-the-seventh-chrome-zero-day-in-2025.html