Google fixed four vulnerabilities in the Chrome web browser on Wednesday, including one that it said has been exploited in the wild.
The V8 JavaScript and WebAssembly engine includes a zero-day vulnerability known as CVE-2025-10585, which has been characterized as a type misunderstanding problem.
Type confusion flaws can have serious repercussions because malicious actors can use them to cause unexpected software behavior, such as arbitrary code execution and program failures.
The vulnerability was found and reported by Google’s Threat Analysis Group (TAG) on September 16, 2025.
As is customary, the business provided no further details regarding the extent of the attempts, who is using the vulnerability, or how it is being used in actual assaults. This keeps additional threat actors from taking advantage read more about Google Patches Chrome Zero-Day CVE-2025-10585 as Active V8 Exploit Threatens Millions.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
