CVE-2025-10585: Google Chromium V8 Type Confusion Vulnerability
Chromium: CVE-2025-10585 Type Confusion in V8
Other sources
Google Chromium contains a type confusion vulnerability in the V8 JavaScript and WebAssembly engine.
— CISA
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. Google is aware that an exploit for CVE-2025-10585 exists in the wild.
— Microsoft
Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
— MITRE
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-10585?
CVE-2025-10585 has been categorized as a high-severity vulnerability due to potential exploitation risks.
How do I fix CVE-2025-10585?
To fix CVE-2025-10585, ensure that you update to the latest version of Microsoft Edge (Chromium-based) available from Microsoft.
What does CVE-2025-10585 affect?
CVE-2025-10585 affects Microsoft Edge (Chromium-based) and any browsers that rely on Chromium for rendering.
Is CVE-2025-10585 actively being exploited?
Yes, there are reports indicating that CVE-2025-10585 is being actively exploited in the wild.
Who is responsible for fixing CVE-2025-10585?
The responsibility for fixing CVE-2025-10585 falls on Microsoft, as it maintains the Edge browser.