HomeSecurityCISA: Chrome zero-day vulnerability in the KEV List

CISA: Chrome zero-day vulnerability in KEV List

The United States Cybersecurity and Infrastructure Security Agency (CISA) has added a serious zero-day vulnerability in Google Chrometo its list of Known Exploitable Vulnerabilities (KEV).

CISA Chrome zero-day vulnerability KEV Catalog

The vulnerability, which is tracked as CVE-2025-10585, has been used by cybercriminals to carry out attacks, which shows the urgent need to apply the appropriate updates.

Google confirmed that it is aware of the existence of an exploit for this vulnerability and has released security updates to address the threat.

See also: Chrome: Vulnerabilities allow data leakage & system crashes

Chrome zero-day: Type Confusion vulnerability

The vulnerability is a type confusion vulnerability in Chrome's V8 JavaScript and WebAssembly engines. Such errors occur when a program attempts to access a resource with an incompatible type, causing the data to be misinterpreted. This can lead to memory corruption, which an attacker could exploit to cause the browser or, worse, execute arbitrary code on the affected system.

The vulnerability was discovered and reported by Google's Threat Analysis Team (TAG) on September 16, 2025.

Google has not disclosed technical details about the specific attacks or the threat actors involved. This is a common practice to prevent wider exploitation before users have a chance to apply the necessary updates.

See also: Vulnerability in SolarWinds Web Help Desk allows RCE execution

This is the sixth Chrome zero-day vulnerability exploited by hackers in 2025, highlighting a persistent trend of attackers targeting browser vulnerabilities:

CVE IDVulnerability TypeDescriptionExploited in the Wild
CVE-2025-10585Type ConfusionA type confusion vulnerability in the V8 JavaScript engine that could be exploited via a malicious webpage.Yes
CVE-2025-6558Improper Input ValidationInsufficient untrusted input validation in ANGLE and GPU components, which allows a remote attacker to perform sandbox escape.Yes
CVE-2025-6554Type ConfusionA type confusion vulnerability in the V8 JavaScript and WebAssembly engine, which could allow an attacker to perform arbitrary read/write operations.Yes
CVE-2025-5419Out-of-Bounds AccessAn “out-of-bounds read and write” vulnerability in the V8 engine that could allow memory corruption when visiting a crafted web page.Yes
CVE-2025-2783Sandbox BypassA critical vulnerability that allows bypassing Chrome's sandbox protection.Yes
CVE-2025-4664Insufficient policy enforcementInsufficient untrusted input validation in ANGLE and GPU components allows a remote attacker to perform sandbox escape.This vulnerability was treated by Google as a zero-day, but it is unclear whether it was actively exploited in malicious attacks.

Google has released updates to protect users from potential attacks.

CISA: Vulnerability CVE-2025-10585

In response to the active exploitation, CISA has directed Federal Agencies (FCEB) to implement the necessary security updates by October 14, 2025.While this directive is mandatory for federal agencies, CISA urges all organizations and individual users to prioritize updating their systems to defend their systems and effectively address potential attacks.

See also: CISA: Shai-Hulud worm has compromised 500+ npm packages

CISA: Chrome zero-day vulnerability in KEV List

To mitigate the risk posed by this vulnerability, users should update their Chrome browser to the latest version. Users can initiate the update by going to the Chrome menu, selecting “Help,” and then “About Google Chrome.” The latest version will be automatically checked and installed. Users of other browsers , such as Microsoft Edge, Brave, Opera, and Vivaldi, are also advised to apply security updates (as soon as they become available from their respective vendors). Enabling automatic updates is strongly recommended to ensure immediate protection against future threats.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS