CVE-2025-10585

Analyzed
Published: 24 Sept 2025, 17:15
Last modified:30 Sept 2025, 13:46

Vulnerability Summary

Overall Risk
High Risk
70/100
CVSS Score
9.8 CRITICAL
v3.1
EPSS Score
4.55% LOW
89%ile 0.00%
CISA KEV
Active
Ransomware
Known Use
Exploits
None found
Dark Web
Not detected
Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Source Identifier: chrome-cve-admin@google.com
CVSSSourceSeverityExploitabilityImpactVector
v4.0n/a
v3.1Primary nvd@nist.gov9.8 CRITICAL3.95.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H...
v3.1 134c704f-9b21-4f2e-91b3-4a467353bcc09.8 CRITICAL3.95.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H...
v3.0n/a
v2.0n/a
4.55%
Current Score
0.00%
89%ile
Percentile Rank
0.00%
Loading chart...
Loading chart...
Access of Resource Using Incompatible Type ('Type Confusion') CWE-843
Description:The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.
Vulnerability Name:Google Chromium V8 Type Confusion Vulnerability
Added to CISA Catalog:23 Sept 2025, 00:00
Action Due:14 Oct 2025, 00:00
Known Ransomware: Ransomware
Required Action:Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

No dark web activity detected for this vulnerability.

No known public exploit code indexed (as of 30 Sept 2025, 13:46).

Exploitation status can change quickly once PoC code appears.

Affected Configurations (CPE)

AND
google chromeVulnerable
Version: *
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
apple macosNot Vulnerable
Version: -
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
linux linux_kernelNot Vulnerable
Version: -
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
microsoft windowsNot Vulnerable
Version: -
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
URLTagsSource
https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_17.htmlrelease notesvendor advisorychrome-cve-admin@google.com
https://issues.chromium.org/issues/445380761issue trackingpermissions requiredchrome-cve-admin@google.com
© 2025 CveMate. All rights reserved.v0.1.3