CVE-2025-10585
Analyzed
Published: 24 Sept 2025, 17:15
Last modified:30 Sept 2025, 13:46
Vulnerability Summary
Overall Risk
High Risk
70/100 CVSS Score
9.8 CRITICAL
v3.1
EPSS Score
4.55% LOW
89%ile 0.00%
CISA KEV
Active
Ransomware
Known Use
Exploits
None found
Dark Web
Not detected
Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Source Identifier: chrome-cve-admin@google.com
CVSS | Source | Severity | Exploitability | Impact | Vector |
---|---|---|---|---|---|
v4.0 | n/a | ||||
v3.1 | Primary nvd@nist.gov | 9.8 CRITICAL | 3.9 | 5.9 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H... |
v3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 CRITICAL | 3.9 | 5.9 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H... |
v3.0 | n/a | ||||
v2.0 | n/a |
4.55%
Current Score
0.00%
89%ile
Percentile Rank
0.00%
Loading chart...
Loading chart...
Access of Resource Using Incompatible Type ('Type Confusion') CWE-843
Description:The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.
Vulnerability Name:Google Chromium V8 Type Confusion Vulnerability
Added to CISA Catalog:23 Sept 2025, 00:00
Action Due:14 Oct 2025, 00:00
Known Ransomware: Ransomware
Required Action:Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
No dark web activity detected for this vulnerability.
No known public exploit code indexed (as of 30 Sept 2025, 13:46).
Exploitation status can change quickly once PoC code appears.
Affected Configurations (CPE)
AND
google chromeVulnerable
Version: *
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
apple macosNot Vulnerable
Version: -
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
linux linux_kernelNot Vulnerable
Version: -
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
microsoft windowsNot Vulnerable
Version: -
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
URL | Tags | Source |
---|---|---|
https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_17.html | release notesvendor advisory | chrome-cve-admin@google.com |
https://issues.chromium.org/issues/445380761 | issue trackingpermissions required | chrome-cve-admin@google.com |