CVE-2025-0291: Type Confusion in V8
Chromium: CVE-2025-0291 Type Confusion in V8
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Type Confusion in V8 in Google Chrome prior to 131.0.6778.264 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
— MITRE
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0291?
CVE-2025-0291 has been classified as a critical vulnerability due to its potential impact on users.
How do I fix CVE-2025-0291?
To fix CVE-2025-0291, ensure that you update Chrome to version 131.0.6778.264 or Microsoft Edge to the latest available version.
Which software is affected by CVE-2025-0291?
CVE-2025-0291 affects Google Chrome versions up to 131.0.6778.264 and Microsoft Edge (Chromium-based) versions prior to the latest update.
What type of vulnerability is CVE-2025-0291?
CVE-2025-0291 is identified as a type confusion vulnerability affecting the rendering engine.
Who is responsible for addressing CVE-2025-0291?
CVE-2025-0291 was assigned by Chrome, and it falls within the responsibility of Google and Microsoft to provide necessary patches.