CVE-2025-13223

Analyzed
Published: 17 Nov 2025, 23:15
Last modified:21 Nov 2025, 18:28

Vulnerability Summary

Overall Risk
High Risk
68/100
AI Analysis
Emergency
Requires Immediate Action
AI Detection
Active in Wild
Exploitation Detected
CVSS Score
8.8 HIGH
CVSS v3.1 (134C704F-9B21-4F2E-91B3-4A467353BCC0)
EPSS Score
30.74% MEDIUM
31% probability 0.00%
CISA KEV
Listed
Google
Ransomware
Known Use
Exploits
None found
Dark Web
Activity detected
Telegram
Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Source Identifier: chrome-cve-admin@google.com
CVSSSourceSeverityExploit.ImpactVector
v4.0n/a
v3.1134c704f-9b21-4f2e-91b3-4a467353bcc08.8 HIGH2.85.9
CVSS:3.1/AV:N/AC:L/PR:N/U...
v3.0n/a
v2.0n/a
16.09%
Current Score
0.00%
95%ile
Percentile Rank
0.00%
Loading chart...
Loading chart...
Access of Resource Using Incompatible Type ('Type Confusion') CWE-843
Description:The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.
Vulnerability Name:Google Chromium V8 Type Confusion Vulnerability
Added to CISA Catalog:19 Nov 2025, 00:00
Action Due:10 Dec 2025, 00:00
Known Ransomware: Ransomware
Required Action:Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Telegram Activity Detected
This vulnerability has been mentioned in monitored Telegram channels, indicating potential threat actor interest.

No known public exploit code indexed (as of 21 Nov 2025, 18:28).

Exploitation status can change quickly once PoC code appears.

Affected Configurations (CPE)

AND
google chromeVulnerable
Version: *
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
apple macosNot Vulnerable
Version: -
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
linux linux_kernelNot Vulnerable
Version: -
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
microsoft windowsNot Vulnerable
Version: -
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
© 2025 CveMate. All rights reserved.v0.1.4