Skip to content
COOEY

EXPOSURES › CVE-2025-10585

CVE-2025-10585

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-09-23 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-10585 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Google Chromium V8 had an unpatched type confusion vulnerability actively exploited in the wild

Google's Chromium V8 engine, a core component of Chrome and ChromeOS, was found to have a type confusion vulnerability that was actively exploited. This indicates a severe security flaw that was not addressed before it was discovered, potentially allowing attackers to execute arbitrary code or commands remotely.

Shame score — A critical vulnerability in a widely-used engine was not patched before it was discovered to be actively exploited, leading to potential remote code execution.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium contains a type confusion vulnerability in the V8 JavaScript and WebAssembly engine.

AFFECTED FEDRAMP PRODUCTS · 3
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized
Mendix Cloud for Government
Siemens Government Technologies
In Process