Active exploitation of type confusion in Chrome's V8 engine
Summary
Hide β²
Show βΌ
Google has patched a zero-day vulnerability in Chrome (CVE-2025-10585), a type confusion issue in the V8 JavaScript and WebAssembly engine. The flaw is actively exploited in the wild, posing a risk to millions of users. The patch is available in Chrome versions 140.0.7339.185/.186 for Windows and macOS, and 140.0.7339.185 for Linux. Users of other Chromium-based browsers should also apply the fixes. The vulnerability can lead to unexpected software behavior, arbitrary code execution, and program crashes. Google's Threat Analysis Group (TAG) discovered and reported the flaw on September 16, 2025. This is the sixth zero-day vulnerability in Chrome exploited or demonstrated in 2025.
Timeline
-
18.09.2025 08:49 π° 1 articles Β· β± 1d ago
Google patches actively exploited zero-day in Chrome's V8 engine
Google has released security updates for Chrome to address a zero-day vulnerability (CVE-2025-10585) in the V8 JavaScript and WebAssembly engine. The flaw is actively exploited in the wild and can lead to arbitrary code execution and program crashes. The patch is available in Chrome versions 140.0.7339.185/.186 for Windows and macOS, and 140.0.7339.185 for Linux. Users of other Chromium-based browsers should also apply the fixes as they become available.
Show sources
- Google Patches Chrome Zero-Day CVE-2025-10585 as Active V8 Exploit Threatens Millions β thehackernews.com β 18.09.2025 08:49
Information Snippets
-
The vulnerability is a type confusion issue in the V8 JavaScript and WebAssembly engine.
First reported: 18.09.2025 08:49π° 1 source, 1 articleShow sources
- Google Patches Chrome Zero-Day CVE-2025-10585 as Active V8 Exploit Threatens Millions β thehackernews.com β 18.09.2025 08:49
-
The flaw is actively exploited in the wild, but specific details about the attacks are not disclosed.
First reported: 18.09.2025 08:49π° 1 source, 1 articleShow sources
- Google Patches Chrome Zero-Day CVE-2025-10585 as Active V8 Exploit Threatens Millions β thehackernews.com β 18.09.2025 08:49
-
The patch is available in Chrome versions 140.0.7339.185/.186 for Windows and macOS, and 140.0.7339.185 for Linux.
First reported: 18.09.2025 08:49π° 1 source, 1 articleShow sources
- Google Patches Chrome Zero-Day CVE-2025-10585 as Active V8 Exploit Threatens Millions β thehackernews.com β 18.09.2025 08:49
-
Users of other Chromium-based browsers should apply the fixes as they become available.
First reported: 18.09.2025 08:49π° 1 source, 1 articleShow sources
- Google Patches Chrome Zero-Day CVE-2025-10585 as Active V8 Exploit Threatens Millions β thehackernews.com β 18.09.2025 08:49
-
Google's Threat Analysis Group (TAG) discovered and reported the flaw on September 16, 2025.
First reported: 18.09.2025 08:49π° 1 source, 1 articleShow sources
- Google Patches Chrome Zero-Day CVE-2025-10585 as Active V8 Exploit Threatens Millions β thehackernews.com β 18.09.2025 08:49
-
This is the sixth zero-day vulnerability in Chrome exploited or demonstrated in 2025.
First reported: 18.09.2025 08:49π° 1 source, 1 articleShow sources
- Google Patches Chrome Zero-Day CVE-2025-10585 as Active V8 Exploit Threatens Millions β thehackernews.com β 18.09.2025 08:49