Categories: Cyber Security News

CISA Warns of Google Chrome 0-Day Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a high-severity zero-day vulnerability in Google Chrome that is being actively exploited in attacks.

The vulnerability, tracked as CVE-2025-10585, has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, signaling an urgent need for users and administrators to take action.

Google has confirmed it is aware that an exploit for this flaw exists in the wild and has released security updates to address the threat.

Understanding the V8 Type Confusion Flaw

The vulnerability is a type confusion weakness within Chrome’s V8 JavaScript and WebAssembly engine. A type confusion flaw (CWE-843) occurs when a program attempts to access a resource with an incompatible type, causing it to misinterpret the data.

This can lead to memory corruption, which an attacker can leverage to crash the browser or, more critically, execute arbitrary code on the affected system.

The flaw was discovered and reported by Google’s own Threat Analysis Group (TAG) on September 16, 2025.

While Google has not disclosed technical details about the specific attacks or the threat actors involved, this is a standard practice to prevent wider exploitation before users have a chance to apply the necessary patches.

This marks the sixth Chrome zero-day vulnerability that has been actively exploited in 2025, highlighting a persistent trend of attackers targeting browser vulnerabilities.

In 2025, Google addressed multiple zero-day vulnerabilities in its Chrome web browser that were actively exploited in the wild. These flaws required urgent updates to protect users from potential attacks.

The table below details the Chrome zero-day vulnerabilities that have been discovered and patched throughout the year.

Sponsored
CVE ID Vulnerability Type Description Exploited in the Wild
CVE-2025-10585 Type Confusion A type confusion flaw in the V8 JavaScript engine that could be exploited via a malicious webpage. Yes
CVE-2025-6558 Improper Input Validation Insufficient validation of untrusted input in the ANGLE and GPU components, allowing a remote attacker to perform a sandbox escape. Yes
CVE-2025-6554 Type Confusion A type confusion vulnerability in the V8 JavaScript and WebAssembly engine, which could allow an attacker to perform arbitrary read/write operations. Yes
CVE-2025-5419 Out-of-Bounds Access An out-of-bounds read and write vulnerability in the V8 engine that could allow memory corruption by visiting a crafted webpage. Yes
CVE-2025-2783 Sandbox Bypass A critical vulnerability that allows for bypassing Chrome’s sandbox protection. Yes
CVE-2025-4664 Insufficient policy enforcement This vulnerability was addressed by Google as a zero-day, but it is unclear if it was actively exploited in malicious attacks. Insufficient validation of untrusted input in the ANGLE and GPU components allows a remote attacker to perform a sandbox escape.

In response to the active exploitation, CISA has directed Federal Civilian Executive Branch (FCEB) agencies to apply the necessary security updates by October 14, 2025, in accordance with Binding Operational Directive (BOD) 22-01.

While this directive is mandatory for federal agencies, CISA strongly urges all organizations and individual users to prioritize patching their systems to defend against potential attacks.

To mitigate the vulnerability, users should update their Chrome browser to the latest version:

  • Windows and macOS: 140.0.7339.185/.186
  • Linux: 140.0.7339.185

Users can initiate the update by navigating to Chrome’s menu, selecting “Help,” and then “About Google Chrome,” which will trigger an automatic check for and installation of the latest version.

Users of other Chromium-based browsers, such as Microsoft Edge, Brave, Opera, and Vivaldi, are also advised to apply security updates as soon as they become available from their respective vendors.

Enabling automatic updates is highly recommended to ensure prompt protection against future threats.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

The post CISA Warns of Google Chrome 0-Day Vulnerability Exploited in Attacks appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

Liberty Forum in Concord will celebrate the Free State Project

New Hampshire Free Staters will be taking a victory lap in Concord this week at…

2 minutes ago

Dunbarton voters to evaluate switching to SB 2 school meeting format

On Election Day, Dunbarton residents will weigh whether to change the traditional format of their…

2 minutes ago

Caffeine with a side of cozy conversation at Angelo’s, a new South End coffee shop

If you walk into Angelo Gray’s coffee shop and order a plain latte, he’ll raise…

3 minutes ago

Lego’s Smart Brick is here, and it transforms these new Star Wars sets

Lego's new Smart Brick is a pretty big deal. It packs a miniature computer, a…

1 hour ago

Soundcore’s Space 2 are an evolution of its budget headphones

We finally have an update to the Soundcore Space One that launched two and a…

2 hours ago

Everything Coming to Apple TV in March

A new month means a new batch of shows and movies on all of your…

3 hours ago

This website uses cookies.