Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Chrome 140 Update Patches Sixth Zero-Day of 2025

An exploited type confusion in the V8 JavaScript engine tracked as CVE-2025-10585 was found by Google Threat Analysis Group this week.

Chrome security

Google on Wednesday rushed out a Chrome update that resolves a vulnerability exploited in attacks, the sixth zero-day addressed in the browser this year.

Tracked as CVE-2025-10585 and reported by Google’s Threat Analysis Group (TAG) on September 16, the flaw is described as a type confusion in the V8 JavaScript and WebAssembly engine.

Type confusion bugs are memory safety issues that can trigger unexpected software behavior, which could lead to crashes, remote code execution, and other types of attacks.

Using crafted HTML pages, threat actors could exploit type confusion defects in V8 to perform arbitrary read/write operations remotely.

“Google is aware that an exploit for CVE-2025-10585 exists in the wild,” the internet giant notes in its advisory. No details were released on the vulnerability or its exploitation.

The fact that it was reported by Google TAG implies that a spyware vendor might have exploited it. TAG researchers have uncovered numerous security holes exploited by commercial spyware, including bugs in Chrome.

Advertisement. Scroll to continue reading.

The latest browser update also resolves two use-after-free flaws in Dawn (CVE-2025-10500) and WebRTC (CVE-2025-10501), for which Google handed out rewards of $15,000 and $10,000, respectively.

Additionally, the update contains fixes for a heap buffer overflow in the ANGLE graphics engine (CVE-2025-10502) discovered by the Big Sleep AI agent, which Google says can find security defects that attackers already know about and plan on exploiting.

The internet giant has yet to disclose the bug bounty amount to be paid for the ANGLE flaw. No reward will be handed out for the exploited vulnerability because it was discovered internally.

The latest Chrome iteration is now rolling out as versions 140.0.7339.185/.186 for Windows and macOS, and as version 140.0.7339.185 for Linux.

Related: Chrome Update Patches Fifth Zero-Day of 2025

Related: Critical Chrome Vulnerability Earns Researcher $43,000

Related: ChatGPT’s Calendar Integration Can Be Exploited to Steal Emails

Related: DELMIA Factory Software Vulnerability Exploited in Attacks

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more.

Register

This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.

Register

People on the Move

Fable Security has appointed Jacob Berry as Chief Information Security Officer.

iCOUNTER has named Ali Waezzadah as Chief Information Security Officer.

Roger Hale has joined 1Kosmos as Chief Information Security Officer.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.