CVE detail
CVE-2025-10585
Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 29.4 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
18 source links · newest first
- Siemens CADRACISA Alerts
cations, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2005-2096 zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow,
governmentwww.cisa.govJul 21, 2026, 12:00 PM Shadow AI embedded in everyday apps, combined with outdated mobile devices and zero-click exploits, is creating a new and largely unseen mobile risk.
newswww.securityweek.comApr 3, 2026, 11:00 AM- Google fixed a new actively exploited Chrome zero-daySecurity Affairs
Google addressed three vulnerabilities in the Chrome browser, including a high-severity bug already exploited in the wild. Google released security updates to fix three vulnerabilities in the Chrome browser, including a high-severity flaw that threat actors are already exploiting in real-world attacks. “Google is aware that an exploit for 466192044 exists in the wild,” reads […]
newssecurityaffairs.comDec 11, 2025, 6:18 PM For the third time in recent months, Google has found itself scrambling to fix a potentially serious zero-day flaw in the Chrome browser’s V8 JavaScript engine. Addressed on Monday as part of an emergency ‘out-of-band’ patch, the vulnerability identified as CVE-2025-13223 was discovered by Clément Lecigne of Google’s in-house Threat Analysis Group (TAG). At some […]
newswww.csoonline.comNov 18, 2025, 6:16 PM- Google fixed the seventh Chrome zero-day in 2025Security Affairs
Google patched two Chrome flaws, including a V8 type-confusion bug, tracked as including CVE-2025-13223, which was exploited in the wild. Google released Chrome security updates to address two flaws, including a high-severity V8 type confusion bug tracked as CVE-2025-13223 that has been actively exploited in the wild. The Chrome V8 engine is Google’s open-source JavaScript […]
newssecurityaffairs.comNov 18, 2025, 8:59 AM A lot of classic software is reaching end-of-life (EOL) this month. Windows 10, Office 2016 and Exchange Server 2016 have survived after nearly a decade of service. Not far behind, after six years in existence, comes the end of Office 2019 and Exchange Server 2019. While this Patch Tuesday may be cause for celebration at Microsoft with the final updates for these products, I hope you’ve been following this closely and have already migrated to … More →
newswww.helpnetsecurity.comOct 10, 2025, 6:30 AMNo excerpt available.
Mitigationwww.cisa.govSep 24, 2025, 5:15 PM- https://cert-portal.siemens.com/productcert/html/ssa-470355.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comSep 24, 2025, 5:15 PM - https://issues.chromium.org/issues/445380761issues.chromium.org
No excerpt available.
Exploitissues.chromium.orgSep 24, 2025, 5:15 PM - https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_17.htmlchromereleases.googleblog.com
No excerpt available.
Vendor Advisorychromereleases.googleblog.comSep 24, 2025, 5:15 PM U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Google Chromium flaw, tracked as CVE-2025-10585, to its Known Exploited Vulnerabilities (KEV) catalog. In mid-September, Google released security updates to address four vulnerabilities in the Chrome web browser, including CVE-2025-10585, which […]
newssecurityaffairs.comSep 23, 2025, 6:50 PM- 22nd September – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 22nd September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Several major European airports including Heathrow, Berlin, Brussels, Dublin, and Cork have experienced a cyber-attack, resulting in disruptions to electronic check-in and baggage drop systems using Collins Aerospace’s MUSE software. The incident […]
vendorresearch.checkpoint.comSep 22, 2025, 8:31 AM A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. A cyberattack on Collins Aerospace disrupted operations at major European airports CISA warns of malware deployed […]
newssecurityaffairs.comSep 21, 2025, 3:44 PM- Week in review: Chrome 0-day fixed, npm supply chain attack, LinkedIn data used for AIHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Most enterprise AI use is invisible to security teams Most enterprise AI activity is happening without the knowledge of IT and security teams. According to Lanai, 89% of AI use inside organizations goes unseen, creating risks around data privacy, compliance, and governance. Arkime: Open-source network analysis and packet capture system Arkime is an open-source system for large-scale network analysis and … More →
newswww.helpnetsecurity.comSep 21, 2025, 8:00 AM Google has released a security update for the Chrome stable channel to fix a zero‑day vulnerability (CVE-2025-10585) reported by its Threat Analysis Group (TAG) on Tuesday. “Google is aware that an exploit for CVE-2025-10585 exists in the wild,” the company announced. About CVE-2025-10585 Like CVE-2025-6554, which was fixed earlier this year, CVE-2025-10585 is a type confusion vulnerability in V8, Chrome’s JavaScript and WebAssembly engine. Unfortunately, that’s the only information Google has shared about it. As … More →
newswww.helpnetsecurity.comSep 18, 2025, 12:25 PMGoogle has issued a Chrome update to fix four high priority flaws including one zero-day, zero-click vulnerability.
newswww.malwarebytes.comSep 18, 2025, 10:15 AM- CVE-2025-10585 is the sixth actively exploited Chrome zero-day patched by Google in 2025Security Affairs
Google addressed four vulnerabilities affecting its Chrome web browser, including one that has been exploited in the wild. Google released security updates to address four vulnerabilities in the Chrome web browser, including CVE-2025-10585, which has reportedly been exploited in the wild. “Google is aware that an exploit for CVE-2025-10585 exists in the wild.” reads the […]
newssecurityaffairs.comSep 18, 2025, 8:57 AM - Chrome 140 Update Patches Sixth Zero-Day of 2025SecurityWeek
An exploited type confusion in the V8 JavaScript engine tracked as CVE-2025-10585 was found by Google Threat Analysis Group this week.
newswww.securityweek.comSep 18, 2025, 7:54 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2025-13223CVSS 8.8 · High
Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity…
- CVE-2026-14148CVSS 6.5 · Medium
Type Confusion in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (C…
- CVE-2026-13883CVSS 9.6 · Critical
Type Confusion in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security sever…
- CVE-2026-13776CVSS 9.8 · Critical
Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a cra…
- CVE-2026-11662CVSS 8.8 · High
Type Confusion in Bindings in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium securit…
- CVE-2026-11196CVSS 6.5 · Medium
Type Confusion in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted XML file. (Ch…