EXPOSURES › CVE-2025-10585
CVE-2025-10585
HIGH ⌖ ON CISA KEV · EXPLOITEDGoogle Chromium V8 had an unpatched type confusion vulnerability actively exploited in the wild
Google's Chromium V8 engine, a core component of Chrome and ChromeOS, was found to have a type confusion vulnerability that was actively exploited. This indicates a severe security flaw that was not addressed before it was discovered, potentially allowing attackers to execute arbitrary code or commands remotely.
Shame score — A critical vulnerability in a widely-used engine was not patched before it was discovered to be actively exploited, leading to potential remote code execution.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium contains a type confusion vulnerability in the V8 JavaScript and WebAssembly engine.
| PRODUCT | STATUS |
|---|---|
| Google Services (Google Cloud Platform Products and underlying Infrastructure) Google |
Authorized |
| Google Workspace Google |
Authorized |
| Mendix Cloud for Government Siemens Government Technologies |
In Process |