PT-2025-27478 · Google +1 · Google Chrome +2

Clément Lecigne

·

Published

2025-06-30

·

Updated

2025-07-25

·

CVE-2025-6554

CVSS v2.0
10
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C

**Name of the Vulnerable Software and Affected Versions:**

Google Chrome versions prior to 138.0.7204.96

**Description:**

A type confusion vulnerability exists in the V8 JavaScript engine in Google Chrome, prior to version 138.0.7204.96. This flaw allows a remote attacker to perform arbitrary read/write operations via a crafted HTML page. This vulnerability is actively exploited in the wild and has been observed being used to target high-risk individuals with spyware. The vulnerability allows attackers to execute arbitrary code, potentially leading to remote code execution (RCE). Exploitation has been observed through phishing sites targeting cryptocurrency wallet data.

**Recommendations:**

Update Google Chrome to version 138.0.7204.96 or later.

Exploit

Fix

DoS

RCE

Type Confusion

Weakness Enumeration

Related Identifiers

BDU:2025-07783
CVE-2025-6554
DSA-5955-1

Affected Products

Debian
Google Chrome
V8 Javascript Engine