Google fixes actively exploited Chrome zero-day vulnerability (CVE-2025-10585)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-10585 | Actively Exploited V8 Type Confusion in Google Chrome (Heap Corruption) CVE-2025-10585 is a type confusion flaw (CWE-843) in the V8 JavaScript engine in Google Chrome and Chromium prior to version 140.0.7339.185. A remote attacker can trigger it via a crafted HTML page processed by the browser, causing V8 to mishandle object types and potentially exploit heap corruption, which can yield code execution in the browser. Any user or system running an affected Chrome/Chromium build is exposed, and Siemens Cadra is also listed as affected in the CPE data. The flaw is being actively exploited in the wild: Google patched it as a zero-day, CISA added it to the Known Exploited Vulnerabilities catalog on 2025-09-23, and reporting describes it as the sixth actively exploited Chrome zero-day of 2025. Do: Update Google Chrome to 140.0.7339.185 or later immediately (verify via Settings > About Chrome or through enterprise browser management); because the flaw is in CISA's KEV catalog, federal agencies must apply vendor mitigations per BOD 22-01 guidance or discontinue use if mitigations are unavailable. Organizations running products that embed Chromium, including Siemens Cadra per the CPE listing, should contact those vendors for patched builds. No public PoC is known, but in-the-wild exploitation is confirmed, so do not defer patching. | 9.8 | 5% | KEV |
| mass≈3+ billion Chrome users/installations worldwide, plus an unknown number of Chromium-embedded deployments (e.g., Siemens Cadra) | |
| CVE-2025-6554 | Type Confusion in Google Chrome V8 Allows Arbitrary Read/Write (Actively Exploited) CVE-2025-6554 is a type confusion vulnerability (CWE-843) in the V8 JavaScript engine of Google Chrome, affecting versions prior to 138.0.7204.96. A remote attacker can trigger it by inducing a user to open a crafted HTML page, and the flaw permits arbitrary read and write within the browser renderer process. Successful exploitation yields high confidentiality and integrity impact, and V8 type confusion bugs are commonly used as the first stage toward a full browser compromise. Any user of an unpatched Chrome or Chromium-based browser is exposed, and the flaw is being actively exploited in the wild as a zero-day; CISA added it to the Known Exploited Vulnerabilities catalog on 2025-07-02. Ransomware usage is not confirmed (reported as unknown), and no public proof-of-concept is known. Do: Update Chrome to 138.0.7204.96 or later (check chrome://settings/help) and restart the browser to load the patched V8; users of Chromium-derived browsers (Edge, Brave, Opera, etc.) should install their vendor's corresponding V8 patch. Organizations must apply vendor mitigations or follow BOD 22-01 guidance given the KEV listing, and should inventory managed browsers and force-update policies to confirm rollout. | 8.1 | 13% | KEV |
| mass≈3+ billion Chrome users; effectively every desktop Chrome installation running a build older than 138.0.7204.96 |
Full article224 words · extracted from helpnetsecurity.com · click to collapse
Google has released a security update for the Chrome stable channel to fix a zero‑day vulnerability (CVE-2025-10585) reported by its Threat Analysis Group (TAG) on Tuesday.

“Google is aware that an exploit for CVE-2025-10585 exists in the wild,” the company announced.
About CVE-2025-10585
Like CVE-2025-6554, which was fixed earlier this year, CVE-2025-10585 is a type confusion vulnerability in V8, Chrome’s JavaScript and WebAssembly engine.
Unfortunately, that’s the only information Google has shared about it. As per the company’s usual practice, they have refrained from sharing details about the attacks in which the flaw is being exploited.
Google TAG’s involvement in the discovery, though, points to the vulnerability being used by state-sponsored threat actors in targeted attacks.
Google has fixed CVE-2025-10585 in Chrome v140.0.7339.185/.186 for Windows/Mac and v140.0.7339.185 for Linux, along with three other high-severity vulnerabilities, one of which has been reported by Google Big Sleep, its AI-based bug hunter agent.
Users who haven’t switched on automatic updates for the browser are advised to manually upgrade to a fixed version and relaunch the application.
Developers of other popular Chromium-based browsers – Edge, Brave, Opera and Vivaldi – will likely fix CVE-2025-10585 very soon, so those users should update their browsers when they do.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/09/18/chrome-zero-day-vulnerability-cve-2025-10585/