CRITICAL
CVE-2025-10585
CVSS
9.8
KEV
Description
Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Summary dbcve.org
Type confusion vulnerability in V8 JavaScript engine in Google Chrome prior to 140.0.7339.185 allows remote attackers to exploit heap corruption via malicious HTML pages. This memory corruption flaw can potentially enable arbitrary code execution.
Mitigation
Update Google Chrome to version 140.0.7339.185 or later. Deploy browser updates via enterprise patch management tools and verify completion across affected endpoints.
Weakness (CWE)
CWE-843
Type Confusion
EPSS Score
5.39%
Probability of exploitation in next 30 days
92.3th percentile
References
https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_17.html
Release Notes, Vendor Advisory
https://issues.chromium.org/issues/445380761
Issue Tracking, Permissions Required
https://cert-portal.siemens.com/productcert/html/ssa-470355.html
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-10585
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.