The United States Cybersecurity and Infrastructure Security Agency (CISA) has added a serious zero-day vulnerability in Google Chrometo its list of Known Exploitable Vulnerabilities (KEV).

The vulnerability, which is tracked as CVE-2025-10585, has been used by cybercriminals to carry out attacks, which shows the urgent need to apply the appropriate updates.
Google confirmed that it is aware of the existence of an exploit for this vulnerability and has released security updates to address the threat.
See also: Chrome: Vulnerabilities allow data leakage & system crashes
Chrome zero-day: Type Confusion vulnerability
The vulnerability is a type confusion vulnerability in Chrome's V8 JavaScript and WebAssembly engines. Such errors occur when a program attempts to access a resource with an incompatible type, causing the data to be misinterpreted. This can lead to memory corruption, which an attacker could exploit to cause the browser or, worse, execute arbitrary code on the affected system.
The vulnerability was discovered and reported by Google's Threat Analysis Team (TAG) on September 16, 2025.
Google has not disclosed technical details about the specific attacks or the threat actors involved. This is a common practice to prevent wider exploitation before users have a chance to apply the necessary updates.
See also: Vulnerability in SolarWinds Web Help Desk allows RCE execution
This is the sixth Chrome zero-day vulnerability exploited by hackers in 2025, highlighting a persistent trend of attackers targeting browser vulnerabilities:
| CVE ID | Vulnerability Type | Description | Exploited in the Wild |
|---|---|---|---|
| CVE-2025-10585 | Type Confusion | A type confusion vulnerability in the V8 JavaScript engine that could be exploited via a malicious webpage. | Yes |
| CVE-2025-6558 | Improper Input Validation | Insufficient untrusted input validation in ANGLE and GPU components, which allows a remote attacker to perform sandbox escape. | Yes |
| CVE-2025-6554 | Type Confusion | A type confusion vulnerability in the V8 JavaScript and WebAssembly engine, which could allow an attacker to perform arbitrary read/write operations. | Yes |
| CVE-2025-5419 | Out-of-Bounds Access | An “out-of-bounds read and write” vulnerability in the V8 engine that could allow memory corruption when visiting a crafted web page. | Yes |
| CVE-2025-2783 | Sandbox Bypass | A critical vulnerability that allows bypassing Chrome's sandbox protection. | Yes |
| CVE-2025-4664 | Insufficient policy enforcement | Insufficient untrusted input validation in ANGLE and GPU components allows a remote attacker to perform sandbox escape. | This vulnerability was treated by Google as a zero-day, but it is unclear whether it was actively exploited in malicious attacks. |
Google has released updates to protect users from potential attacks.
CISA: Vulnerability CVE-2025-10585
In response to the active exploitation, CISA has directed Federal Agencies (FCEB) to implement the necessary security updates by October 14, 2025.While this directive is mandatory for federal agencies, CISA urges all organizations and individual users to prioritize updating their systems to defend their systems and effectively address potential attacks.
See also: CISA: Shai-Hulud worm has compromised 500+ npm packages

To mitigate the risk posed by this vulnerability, users should update their Chrome browser to the latest version. Users can initiate the update by going to the Chrome menu, selecting “Help,” and then “About Google Chrome.” The latest version will be automatically checked and installed. Users of other browsers , such as Microsoft Edge, Brave, Opera, and Vivaldi, are also advised to apply security updates (as soon as they become available from their respective vendors). Enabling automatic updates is strongly recommended to ensure immediate protection against future threats.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
