CVE-2025-13223Patch(google / cadra)

HIGHCVSS 8.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch google cadra systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

6.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-12-10. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-843

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cadra
  • chrome

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 5 observed days

What's happening

  • Active exploitation reported across 2 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-02-07); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Products
cadrachrome

1 version affected across 2 products

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-02-07: 2Mentions · 2026-02-13: 1Mentions · 2026-05-15: 1Mentions · 2026-06-06: 1Mentions · 2026-09-02: 1PoC Mentioned / Linked · 2026-05-15: 1Active Exploitation · 2026-02-13: 1Active Exploitation · 2026-09-02: 1Patch / Workaround · 2026-02-07: 1Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-09-02: 1Technical Details · 2026-02-13: 1Technical Details · 2026-06-06: 1Technical Details · 2026-09-02: 102-0702-1305-1506-0609-02
Signal classification5 categories
Patch
233.3%
General
116.7%
Active Exploitation
116.7%
PoC
116.7%
Disclosure
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-072
General1Patch1
2026-02-131
Active Exploitation1
2026-05-151
PoC1
2026-06-061
Disclosure1
2026-09-021
Patch1
Full discourse6 posts
  • j j@mistymntncop
    Patch

    Re: CVE-2025-13223 - so we can change the field repr (for SMI and HeapObject) without deopt before extending properties. But we still can't do loads/stores on that field as FieldRepr deps will be installed... https://github.com/v8/v8/commit/9b5250b9980c655c0a9f94ca86effb90f17d0a12

    Post summary

    A commit patching CVE‑2025‑13223 in V8 is referenced, with no evidence of exploitation or a PoC.

    23019151.9K
    3.0K followersView on X
  • _SiCk@encrypted_past
    Disclosure

    More to the point. CVE-2025-9132 - OOB write CVE-2025-12036 - inappropriate implementation CVE-2025-13224 - type confusion (CVSS 8.8) CVE-2025-10585 - type confusion CVE-2025-13223 - type confusion (CVSS 8.8) CVE-2026-3910 - (CVSS 8.8, CISA KEV) Fuck v8.

    Post summary

    The text announces a list of new CVEs with brief vulnerability descriptions and CVSS scores, framing it as a disclosure of recently identified security issues without indicating PoCs, exploitation activity, or patch availability.

    0222142.6K
    2.7K followersView on X
  • j j@mistymntncop
    PoC

    https://exploitbench.ai/env/v8-cve-2025-13223/ how interesting no model was able to solve CVE-2025-13223. I guess i don't feel so bad about failing that one now 😆

    Post summary

    The post links to an exploitbench environment for CVE‑2025‑13223, indicating that a proof‑of‑concept exists, but no exploit code, patch, or active exploitation details are provided.

    000942.7K
    3.0K followersView on X
  • Kambiz 🇺🇸@faceless709
    Active Exploitation

    Details: Key Details on Recent Vulnerabilities: •Active Exploitation (2026): CVE-2026-2441 is the latest, with Google confirming an exploit exists in the wild. •Previous 2025 Threats: Multiple, high-severity "zero-day" vulnerabilities (such as CVE-2025-13223 and CVE-2025-13224) were reported throughout 2025, which affected the V8 engine and allowed for remote code execution via compromised websites. •Impact: These vulnerabilities can allow attackers to install programs, view/delete data, or create new accounts. •Action Required: Update Chrome immediately by navigating to Settings > Help > About Google Chrome to ensure you are running version 145.0.7632.75 or later.

    Post summary

    Google confirms CVE‑2026‑2441 is actively exploited in the wild, urging users to update Chrome to mitigate remote code execution risks.

    01020137
    2.6K followersView on X
  • @pedri77@pedri77
    Patch

    Google patched two Chrome flaws, including a V8 type-confusion bug, tracked as including CVE-2025-13223, which was exploited in the wild. Google released Chrome security updates to address two flaws, including a high-se... https://f.mtr.cool/hjrryc9uel

    Post summary

    Google issued patches for two Chrome vulnerabilities, including CVE‑2025‑13223, which had already been exploited in the wild, underscoring the need for timely updates.

    0000054
    2.1K followersView on X
  • VulnTracker@vuln_tracker
    General

    @mistymntncop You now can see the full detail about CVE-2025-13223 from https://vulntracker.io/cves/CVE-2025-13223 for FREE

    Post summary

    The tweet merely shares a link to a website for full details on CVE-2025-13223, with no additional information provided.

    00000156
    333 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgooglechrome---
Appsiemenscadra---

Explore more