Google Issues Security Fix for Actively Exploited Chrome V8 Zero-Day Vulnerability

Google patched two security holes in its Chrome browser on Monday, one of which has been actively exploited in the wild.

The vulnerability in question is CVE-2025-13223 (CVSS score: 8.8), a type misunderstanding flaw in the WebAssembly and V8 JavaScript engines that might be used to cause program crashes or arbitrary code execution.

According to a description of the vulnerability in the NIST National Vulnerability Database (NVD), Type Confusion in V8 in Google Chrome before 142.0.7444.175 allows a remote attacker to potentially exploit memory corruption via a crafted HTML page.

The issue was found and reported on November 12, 2025, by Cléo Lecigne of Google’s Threat Analysis Group (TAG). Google has not disclosed any information on the scope of the assaults, who may have been targeted, or who is responsible for them.

The IT giant did admit that there is an attack for CVE-2025-13223 in the wild though read more about Google Issues Security Fix for Actively Exploited Chrome V8 Zero-Day Vulnerability.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *