U.S. CISA adds a Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-13223 | Actively Exploited V8 Type Confusion in Google Chrome and Siemens Chromium Components CVE-2025-13223 is a type confusion (CWE-843) in the V8 JavaScript engine of Google Chromium, rated High severity by Chromium. A remote attacker can trigger it by luring a user to a crafted HTML page; because browsing is interactive, successful exploitation requires user action (AV:N/PR:N/UI:R). If exploited, the type confusion can lead to heap corruption, which typically enables arbitrary code execution or sandbox-escape-capable memory corruption in the renderer. Anyone running Google Chrome prior to 142.0.7444.175 is affected, and CISA's CPE data also lists Siemens CADRA as an affected product, consistent with Siemens shipping Chromium-based components; CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-11-19. The headlines indicate this is the seventh Chrome zero-day of the year and that it was patched by Google after being observed under active exploitation in the wild; no public proof-of-concept is cataloged, EPSS puts 30-day exploitation probability at 5.0% (92nd percentile), and ransomware association is unknown. Do: Update Google Chrome to 142.0.7444.175 or later on all endpoints, including managed fleets and kiosk deployments, and verify the patched version in chrome://version. Because the flaw is on the CISA KEV list (added 2025-11-19), federal agencies must apply vendor mitigations or follow BOD 22-01 guidance by the required deadline. Organizations running Siemens CADRA or other Siemens products embedding Chromium V8 should check Siemens productCERT advisories for affected versions and updated builds, and prioritize patching internet-facing or user-workstation contexts where untrusted web content is rendered. | 8.8 | 5% | KEV |
| massbillions of Chrome installations worldwide (Chrome has an estimated 3+ billion users), with Siemens CADRA deployments adding an unquantified industrial niche |
Full article369 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
November 19, 2025

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, tracked as CVE-2025-13223, to its Known Exploited Vulnerabilities (KEV) catalog.
This week, Google released Chrome security updates to address two flaws, including a high-severity V8 type confusion bug tracked as CVE-2025-13223 that has been actively exploited in the wild.
The Chrome V8 engine is Google’s open-source JavaScript and WebAssembly engine, written in C++, that executes code for browsers like Google Chrome and applications like Node.js.
A type confusion issue happens when software misinterprets a piece of memory as the wrong type of object. This confusion can let attackers corrupt memory, crash the program, or execute malicious code. It’s common in C/C++ apps like browsers, where weak memory safety makes such exploits possible.
An attacker can trigger the vulnerability via a crafted HTML page to achieve code execution or lead to crashes.
The flaw impacts the V8 script engine in Google Chrome before 142.0.7444.175.
“Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)” reads the NIST’s advisory.
“Google is aware that an exploit for CVE-2025-13223 exists in the wild.” reads the advisory.
Clément Lecigne of Google’s Threat Analysis Group (TAG) reported the vulnerability on November 12, 2025. Google’s TAG team investigates attacks by nation-state actors and commercial spyware vendors. One of these threat actors likely exploited the issue in the wild. As usual, Google has not shared any details on the attacks exploiting this vulnerability.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the vulnerabilities by December 10, 2025.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/184856/hacking/u-s-cisa-adds-a-google-chromium-v8-flaw-to-its-known-exploited-vulnerabilities-catalog.html