CVE-2025-10585Active Exploitation(google / cadra)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch google cadra systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

4.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-10-14. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-843

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cadra
  • chrome

Threat summary

  • Active exploitation appears in 3 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-22); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
cadrachrome

1 version affected across 2 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-22: 1Mentions · 2026-06-06: 1Mentions · 2026-07-07: 1Active Exploitation · 2026-03-22: 1Active Exploitation · 2026-06-06: 1Active Exploitation · 2026-07-07: 1Patch / Workaround · 2026-03-22: 1Patch / Workaround · 2026-07-07: 1Technical Details · 2026-03-22: 1Technical Details · 2026-06-06: 1Technical Details · 2026-07-07: 103-2206-0607-07
Signal classification2 categories
Active Exploitation
266.7%
Disclosure
133.3%
Classification over time
DateTotalLabels
2026-03-221
Active Exploitation1
2026-06-061
Disclosure1
2026-07-071
Active Exploitation1
Full discourse3 posts
  • Aquads.xyz@_Aquads_
    Active Exploitation

    Google has released emergency updates to patch multiple actively exploited zero-day vulnerabilities in Chrome in early 2026, including CVE-2026-3909 (Skia out-of-bounds write) and CVE-2026-3910 (V8 inappropriate implementation). These critical flaws allow remote attackers to execute code via crafted websites, affecting desktop and mobile users. Update immediately to version 146.0.7680+. BleepingComputer BleepingComputer +3 Recent & Active Chrome Exploits (2025-2026) March 2026 (CVE-2026-3909/3910): Emergency patches for two zero-days, one in the Skia graphics library and another in the V8 JavaScript engine [3, BleepingComputer]. February 2026 (CVE-2026-2441): The first actively exploited zero-day of 2026 was patched in February, targeting Chrome, Android, and ChromeOS. February 2026 (CSS Sandbox Escape): A critical vulnerability in the CSS engine was reported to allow sandbox escapes, requiring immediate extension auditing and browser updates [2, Instagram]. December 2025 (CVE-2025-14174): An out-of-bounds memory access vulnerability in ANGLE was exploited, prompting urgent CISA action [12, The Hacker News]. September-November 2025 (CVE-2025-10585): A type confusion vulnerability in the V8 engine was actively exploited in the wild [7, YouTube]. YouTube YouTube +4 Vulnerability Types and Impact V8 Engine Vulnerabilities: The V8 JavaScript/WebAssembly engine is a frequent target for "type confusion" or "inappropriate implementation" bugs, allowing attackers to escape the browser sandbox. Out-of-Bounds (OOB) Write/Memory Access: Flaws in components like Skia or ANGLE allow attackers to write data outside intended memory areas, resulting in crashes or code execution. Remote Code Execution (RCE): Many of these exploits permit attackers to execute arbitrary code on the victim's machine, allowing them to steal data or install malware. CIS Center for Internet Security CIS Center for Internet Security +4 How to Protect Yourself Update Now: Go to chrome://settings/help to force an update to the latest version. Restart Chrome: Patches are only applied after restarting the browser. Check Extensions: Review installed extensions to ensure they are not malicious, as some attacks target browser security, per Instagram. Automatic Updates: Keep automatic updates enabled for your OS and browser

    Post summary

    Google released emergency patches for CVE‑2026‑3909 and CVE‑2026‑3910, both actively exploited zero‑days enabling remote code execution via Skia and V8 flaws, and urged immediate updates.

    791143327
    686 followersView on X
  • _SiCk@encrypted_past
    Disclosure

    More to the point. CVE-2025-9132 - OOB write CVE-2025-12036 - inappropriate implementation CVE-2025-13224 - type confusion (CVSS 8.8) CVE-2025-10585 - type confusion CVE-2025-13223 - type confusion (CVSS 8.8) CVE-2026-3910 - (CVSS 8.8, CISA KEV) Fuck v8.

    Post summary

    The post catalogs a series of CVEs with their vulnerability types and CVSS scores, noting one on the CISA KEV list for possible exploitation, but does not provide PoCs, exploit code, patches, or corrective claims.

    0222142.6K
    2.7K followersView on X
  • CVE Brief@DailyCVEBrief
    Active Exploitation

    LOOK BACK — Google TAG found a zero-day in Chrome's V8 engine on Sept 16, 2025. The fix shipped the NEXT DAY. CVE-2025-10585 was Chrome's 6th exploited zero-day of the year — a type confusion in a bug class Google admits memory-safe languages can't fix. https://t.co/KzyFG90V9R

    Post summary

    The tweet reports that Google TAG uncovered CVE‑2025‑10585, a type‑confusion zero‑day in Chrome’s V8 engine, which was the sixth exploited zero‑day of 2025, with the fix shipped the following day; no PoC or exploit code is provided.

    10000138
    20 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgooglechrome---
Appsiemenscadra---

Explore more