PT-2025-38298 · Google +1 · Google Chrome +1
Published
2025-01-01
·
Updated
2025-11-07
·
CVE-2025-10585
CVSS v3.1
9.8
9.8
Critical
| Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 140.0.7339.185
Microsoft Edge (Chromium-based) versions prior to 140.0.7339.185
Opera versions prior to 122.0.5643.51
Opera GX versions prior to 122.0.5643.52
Opera Air versions prior to 121.0.5600.92
Opera for Android versions prior to 91.5
Description
Google Chrome, and other Chromium-based browsers, are affected by a high-severity zero-day vulnerability (CVE-2025-10585). This is a type confusion flaw within the V8 JavaScript and WebAssembly engine. Attackers are actively exploiting this vulnerability in the wild. The flaw allows for remote code execution (RCE) via a crafted HTML page, potentially leading to complete system compromise. Exploitation does not require user interaction. This is the sixth zero-day vulnerability patched in Chrome this year. The vulnerability impacts systems running on Windows, macOS, and Linux. It is reported that the vulnerability primarily affects arm64 architecture. Attackers are leveraging this flaw to target cryptocurrency wallets, potentially draining funds and stealing private keys.
Recommendations
Update Google Chrome to version 140.0.7339.185 or later.
Update Microsoft Edge (Chromium-based) to version 140.0.7339.185 or later.
Update Opera to version 122.0.5643.51 or later.
Update Opera GX to version 122.0.5643.52 or later.
Update Opera Air to version 121.0.5600.92 or later.
Update Opera for Android to version 91.5 or later.
Restart your browser after applying the update to ensure the changes take effect.
Exploit
Fix
DoS
RCE
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
BDU:2025-11457
CVE-2025-10585
DSA-6004-1
Affected Products
Google Chrome
Debian
References · 221
- 🔥 https://github.com/AdityaBhatt3010/CVE-2025-10585-The-Chrome-V8-Zero-Day⭐ 1 · Exploit
- https://osv.dev/vulnerability/DSA-6004-1 · Vendor Advisory
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-10502 · Security Note
- https://security-tracker.debian.org/tracker/CVE-2025-10585 · Vendor Advisory
- https://bdu.fstec.ru/vul/2025-11455 · Security Note
- https://security-tracker.debian.org/tracker/source-package/chromium · Vendor Advisory
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-10500 · Security Note
- https://safe-surf.ru/specialists/bulletins-nkcki/725720 · Security Note
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-10585 · Vendor Advisory
- https://bdu.fstec.ru/vul/2025-11453 · Security Note
- https://bdu.fstec.ru/vul/2025-11454 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-10585 · Security Note
- https://bdu.fstec.ru/vul/2025-11457 · Security Note
- https://nvd.nist.gov/vuln/detail/CVE-2025-10585 · Security Note
- https://security-tracker.debian.org/tracker/DSA-6004-1 · Vendor Advisory