CRITICAL

CVE-2025-10585

Google Chrome 2025-09-24 CVSS v3.1
CVSS
9.8
KEV

Description

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Summary dbcve.org

Type confusion vulnerability in V8 JavaScript engine in Google Chrome prior to 140.0.7339.185 allows remote attackers to exploit heap corruption via malicious HTML pages. This memory corruption flaw can potentially enable arbitrary code execution.

Mitigation

Update Google Chrome to version 140.0.7339.185 or later. Deploy browser updates via enterprise patch management tools and verify completion across affected endpoints.

Weakness (CWE)

CWE-843 Type Confusion

EPSS Score

5.39%
Probability of exploitation in next 30 days
92.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE