Last seen September 22, 2025

CVE-2025-10585 Security Incident affecting Chromium V8

Evidence indicates that Chromium V8 is affected by a security issue. Exploitation evidence is classified as confirmed in the wild.

Technical Severity
High severity
Lifecycle Status

STABLE

What Happened

Evidence indicates that Chromium V8 is affected by a security issue. Exploitation evidence is classified as confirmed in the wild.

Why This Matters

Current evidence identifies a security issue involving Chromium V8, but does not yet support a more specific impact claim.

Recommended Action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Confirm whether Chromium V8 is present in your environment and review the affected configuration.

Exposure

Recommended Response
First Seen

Sep 22, 2025 05:30

Last Seen

Sep 22, 2025 05:30

Exploitation status: CONFIRMED_IN_THE_WILD

Primary entities:

Google Chromium V8 CVE-2025-10585

Authoritative Intelligence

CVE CVE-2025-10585 Incident identifier
NVD CVSS 9.8 CRITICAL NVD
FIRST EPSS 0.054 92.0 pct
CWE CWE-843 Weakness classification

Provider evidence: NVD, OSV, CISA KEV, FIRST EPSS

EPSS is a vulnerability exploitation probability signal, not proof that your environment is exposed. CISA KEV means known exploitation of the vulnerability, not that your system was exploited.

Timeline

  • Incident first seen
    Sep 22, 2025 05:30

    BugSkan first recorded this incident.

  • ⚡ Weekly Recap: Chrome 0-Day, AI Hacking Tools, DDR5 Bit-Flips, npm Worm & More - The Hacker News
    Sep 22, 2025 05:30

    thehackernews.com · Vulnerability

Sources

⚡ Weekly Recap: Chrome 0-Day, AI Hacking Tools, DDR5 Bit-Flips, npm Worm & More - The Hacker News

thehackernews.com · Sep 22, 2025 05:30

Google has released emergency security updates for Chrome to patch CVE-2025-10585, an actively exploited zero-day vulnerability. This critical type confusion flaw resides within the V8 JavaScript and WebAssembly engine, confirmed to be exploited in the wild.

Open publisher source

Watchlist Match

Want personalized relevance?

Create an account to see which incidents overlap with the technologies you monitor.

← Back to incident intelligence