PT-2025-27478 · Google+4 · V8 Javascript Engine+5
Clément Lecigne
·
Published
2025-06-30
·
Updated
2026-03-18
·
CVE-2025-6554
CVSS v2.0
10
High
| AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 138.0.7204.96
Description
Google Chrome contains a type confusion vulnerability in the V8 JavaScript engine. This flaw allows a remote attacker to perform arbitrary read/write operations via a crafted HTML page, potentially leading to remote code execution (RCE). This vulnerability (CVE-2025-6554) is actively exploited in the wild and has been observed being used by nation-state actors. The vulnerability is related to a flaw in the V8 engine's Ignition bytecode generator, leading to out-of-bounds array corruption. Proof-of-concept (PoC) code is publicly available. The vulnerability affects Chrome and Chromium-based browsers like Microsoft Edge and Opera.
Recommendations
Update Google Chrome to version 138.0.7204.96 or later.
Exploit
Fix
RCE
DoS
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Google Chrome
Red Os
V8 Javascript Engine