PT-2025-27478 · Google +3 · V8 Javascript Engine +4

Clément Lecigne

·

Published

2025-06-30

·

Updated

2025-10-17

·

CVE-2025-6554

CVSS v2.0
10
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 138.0.7204.96 Microsoft Edge versions prior to 138.0.7204.96 Opera versions prior to 138.0.7204.96 Chromium versions prior to 138.0.7204.96
Description A type confusion vulnerability exists in the V8 JavaScript engine in Google Chrome and Chromium-based browsers. This flaw, tracked as CVE-2025-6554, allows a remote attacker to perform arbitrary read/write operations via a crafted HTML page. This vulnerability is actively exploited in the wild, with reports indicating nation-state actors are leveraging it. The vulnerability allows attackers to execute arbitrary code, potentially leading to system compromise. A proof-of-concept exploit is publicly available, increasing the risk of widespread attacks. The vulnerability is a type confusion flaw that can lead to remote code execution.
Recommendations Update Google Chrome to version 138.0.7204.96 or later. Update Microsoft Edge to version 138.0.7204.96 or later. Update Opera to version 138.0.7204.96 or later. Update Chromium to version 138.0.7204.96 or later.

Exploit

Fix

DoS

RCE

Type Confusion

Weakness Enumeration

Related Identifiers

BDU:2025-07783
CVE-2025-6554
DSA-5955-1

Affected Products

Astra Linux
Debian
Google Chrome
Red Os
V8 Javascript Engine