CVE-2025-13224Active Exploitation(apple / chrome)

MEDIUMCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch apple chrome systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-843

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-13); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-13: 1Mentions · 2026-06-06: 1Active Exploitation · 2026-02-13: 1Active Exploitation · 2026-06-06: 1Patch / Workaround · 2026-02-13: 1Technical Details · 2026-02-13: 1Technical Details · 2026-06-06: 102-1306-06
Signal classification2 categories
Active Exploitation
150.0%
Disclosure
150.0%
Classification over time
DateTotalLabels
2026-02-131
Active Exploitation1
2026-06-061
Disclosure1
Full discourse2 posts
  • _SiCk@encrypted_past
    Disclosure

    More to the point. CVE-2025-9132 - OOB write CVE-2025-12036 - inappropriate implementation CVE-2025-13224 - type confusion (CVSS 8.8) CVE-2025-10585 - type confusion CVE-2025-13223 - type confusion (CVSS 8.8) CVE-2026-3910 - (CVSS 8.8, CISA KEV) Fuck v8.

    Post summary

    The post lists several newly disclosed CVEs with brief vulnerability type descriptions and CVSS scores, including one CISA KEV, but provides no exploitation code or mitigation details.

    0222142.6K
    2.7K followersView on X
  • Kambiz 🇺🇸@faceless709
    Active Exploitation

    Details: Key Details on Recent Vulnerabilities: •Active Exploitation (2026): CVE-2026-2441 is the latest, with Google confirming an exploit exists in the wild. •Previous 2025 Threats: Multiple, high-severity "zero-day" vulnerabilities (such as CVE-2025-13223 and CVE-2025-13224) were reported throughout 2025, which affected the V8 engine and allowed for remote code execution via compromised websites. •Impact: These vulnerabilities can allow attackers to install programs, view/delete data, or create new accounts. •Action Required: Update Chrome immediately by navigating to Settings > Help > About Google Chrome to ensure you are running version 145.0.7632.75 or later.

    Post summary

    The text reports that CVE-2026-2441 is actively exploited in the wild, provides patch instructions for Chrome, and includes technical details about the vulnerability.

    01020137
    2.6K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more