Skip to main content

CVE detail

CVE-2025-10585

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS 9.8 · CriticalBuzz score 74.4KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 74.4

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 29.4 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
29.4
18 evidence mentions in the snapshot
Diversity score
20.0
11 sources across 6 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
1
within the 30d window
Peak daily
1
highest bucket

Evidence

Source links by recency

Newest mentions first
18 source links · newest first
  • Siemens CADRACISA Alerts

    cations, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2005-2096 zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow,

    governmentwww.cisa.govJul 21, 2026, 12:00 PM
  • Shadow AI embedded in everyday apps, combined with outdated mobile devices and zero-click exploits, is creating a new and largely unseen mobile risk.

    newswww.securityweek.comApr 3, 2026, 11:00 AM
  • Google addressed three vulnerabilities in the Chrome browser, including a high-severity bug already exploited in the wild. Google released security updates to fix three vulnerabilities in the Chrome browser, including a high-severity flaw that threat actors are already exploiting in real-world attacks. “Google is aware that an exploit for 466192044 exists in the wild,” reads […]

    newssecurityaffairs.comDec 11, 2025, 6:18 PM
  • For the third time in recent months, Google has found itself scrambling to fix a potentially serious zero-day flaw in the Chrome browser’s V8 JavaScript engine. Addressed on Monday as part of an emergency ‘out-of-band’ patch, the vulnerability identified as CVE-2025-13223 was discovered by Clément Lecigne of Google’s in-house Threat Analysis Group (TAG). At some […]

    newswww.csoonline.comNov 18, 2025, 6:16 PM
  • Google fixed the seventh Chrome zero-day in 2025Security Affairs

    Google patched two Chrome flaws, including a V8 type-confusion bug, tracked as including CVE-2025-13223, which was exploited in the wild. Google released Chrome security updates to address two flaws, including a high-severity V8 type confusion bug tracked as CVE-2025-13223 that has been actively exploited in the wild. The Chrome V8 engine is Google’s open-source JavaScript […]

    newssecurityaffairs.comNov 18, 2025, 8:59 AM
  • A lot of classic software is reaching end-of-life (EOL) this month. Windows 10, Office 2016 and Exchange Server 2016 have survived after nearly a decade of service. Not far behind, after six years in existence, comes the end of Office 2019 and Exchange Server 2019. While this Patch Tuesday may be cause for celebration at Microsoft with the final updates for these products, I hope you’ve been following this closely and have already migrated to … More →

    newswww.helpnetsecurity.comOct 10, 2025, 6:30 AM
  • No excerpt available.

    Mitigationwww.cisa.govSep 24, 2025, 5:15 PM
  • https://cert-portal.siemens.com/productcert/html/ssa-470355.htmlcert-portal.siemens.com

    No excerpt available.

    Vendor Advisorycert-portal.siemens.comSep 24, 2025, 5:15 PM
  • https://issues.chromium.org/issues/445380761issues.chromium.org

    No excerpt available.

    Exploitissues.chromium.orgSep 24, 2025, 5:15 PM
  • https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_17.htmlchromereleases.googleblog.com

    No excerpt available.

    Vendor Advisorychromereleases.googleblog.comSep 24, 2025, 5:15 PM
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Google Chromium flaw, tracked as CVE-2025-10585, to its Known Exploited Vulnerabilities (KEV) catalog. In mid-September, Google released security updates to address four vulnerabilities in the Chrome web browser, including CVE-2025-10585, which […]

    newssecurityaffairs.comSep 23, 2025, 6:50 PM
  • 22nd September – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 22nd September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Several major European airports including Heathrow, Berlin, Brussels, Dublin, and Cork have experienced a cyber-attack, resulting in disruptions to electronic check-in and baggage drop systems using Collins Aerospace’s MUSE software. The incident […]

    vendorresearch.checkpoint.comSep 22, 2025, 8:31 AM
  • A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. A cyberattack on Collins Aerospace disrupted operations at major European airports CISA warns of malware deployed […]

    newssecurityaffairs.comSep 21, 2025, 3:44 PM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Most enterprise AI use is invisible to security teams Most enterprise AI activity is happening without the knowledge of IT and security teams. According to Lanai, 89% of AI use inside organizations goes unseen, creating risks around data privacy, compliance, and governance. Arkime: Open-source network analysis and packet capture system Arkime is an open-source system for large-scale network analysis and … More →

    newswww.helpnetsecurity.comSep 21, 2025, 8:00 AM
  • Google has released a security update for the Chrome stable channel to fix a zero‑day vulnerability (CVE-2025-10585) reported by its Threat Analysis Group (TAG) on Tuesday. “Google is aware that an exploit for CVE-2025-10585 exists in the wild,” the company announced. About CVE-2025-10585 Like CVE-2025-6554, which was fixed earlier this year, CVE-2025-10585 is a type confusion vulnerability in V8, Chrome’s JavaScript and WebAssembly engine. Unfortunately, that’s the only information Google has shared about it. As … More →

    newswww.helpnetsecurity.comSep 18, 2025, 12:25 PM
  • Google has issued a Chrome update to fix four high priority flaws including one zero-day, zero-click vulnerability.

    newswww.malwarebytes.comSep 18, 2025, 10:15 AM
  • Google addressed four vulnerabilities affecting its Chrome web browser, including one that has been exploited in the wild. Google released security updates to address four vulnerabilities in the Chrome web browser, including CVE-2025-10585, which has reportedly been exploited in the wild. “Google is aware that an exploit for CVE-2025-10585 exists in the wild.” reads the […]

    newssecurityaffairs.comSep 18, 2025, 8:57 AM
  • An exploited type confusion in the V8 JavaScript engine tracked as CVE-2025-10585 was found by Google Threat Analysis Group this week.

    newswww.securityweek.comSep 18, 2025, 7:54 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence