CVE-2025-6554Patch(apple / chrome)

CRITICALCVSS 8.1 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch apple chrome systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-07-23. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-843

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 5 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Peaked 4d ago at 1 mentions (2026-02-24); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-02-24: 1Mentions · 2026-03-18: 1Mentions · 2026-05-07: 1Mentions · 2026-05-18: 1Mentions · 2026-07-20: 1PoC Mentioned / Linked · 2026-03-18: 1PoC Mentioned / Linked · 2026-05-07: 1Exploit Tool / Code · 2026-03-18: 1Active Exploitation · 2026-03-18: 1Patch / Workaround · 2026-02-24: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-18: 102-2403-1805-0705-1807-20
Signal classification5 categories
Patch
120.0%
Active Exploitation
120.0%
PoC
120.0%
Disclosure
120.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-241
Patch1
2026-03-181
Active Exploitation1
2026-05-071
PoC1
2026-05-181
Disclosure1
2026-07-201
General1
Full discourse5 posts
  • 0xor0ne@0xor0ne
    Active Exploitation

    CVE-2025-6554: in-the-wild V8 the_hole based vulnerability analysis and exploit Bug analysis by @r3tr074: https://retr0.zip/blog/cve-2025-6554-the-rabbit-hole.html PoC by @mistymntncop: https://github.com/mistymntncop/CVE-2025-6554 #infosec https://t.co/dUwWgwzFy0

    Post summary

    The tweet confirms that CVE‑2025‑6554 is being actively exploited in the wild, with a PoC and exploit code available, but no patch or mitigation information is provided.

    0270126786.7K
    88.7K followersView on X
  • reverseame@reverseame
    PoC

    CVE-2025-6554: The (rabbit) Hole #CVE20256554 #V8Exploit #TheHoleLeak #TDZBypass #TypeConfusion https://retr0.zip/blog/cve-2025-6554-the-rabbit-hole.html

    Post summary

    The post announces CVE‑2025‑6554 and provides a link that presumably hosts a proof of concept; key tags point to a type‑confusion issue, yet there is no evidence of active exploitation, patch release, or debunking.

    020752.0K
    22.4K followersView on X
  • stop saying “bayesian”@soymoduh
    General

    @jtregunna @GrowlerEnjooyer @jedisct1 @schteppe > So what you're saying is discipline is fine, you don't need memory safety in a language if you care about the code you write? No, that is not the point. Would you consider JavaScript memory safe? Yes? Then what is this? https://nvd.nist.gov/vuln/detail/CVE-2025-6554

    Post summary

    The tweet simply points to the NVD page for CVE-2025-6554 without offering additional detail, exploitation evidence, or remediation information.

    10090207
    22 followersView on X
  • Andre Gironda@AndreGironda
    Patch

    Grafana security update: Critical severity security release for CVE-2025-5959, CVE-2025-6554, CVE-2025-6191 and CVE-2025-6192 in Grafana Image Renderer plugin and Synthetic Monitoring Agent -- https://grafana.com/blog/grafana-security-update-critical-severity-security-release-for-cve-2025-5959-cve-2025-6554-cve-2025-6191-and-cve-2025-6192-in-grafana-image-renderer-plugin-and-synthetic-monitoring-agent

    Post summary

    Grafana released a critical security update addressing four CVEs affecting the Image Renderer plugin and Synthetic Monitoring Agent, providing patches to mitigate the vulnerabilities.

    01031208
    3.6K followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Disclosure

    🚨 Chrome V8 Sandbox Escape: 3 Primitives for Arbitrary Memory Read/Write (#CVE-2025-6554 Explained) + Video https://undercodetesting.com/chrome-v8-sandbox-escape-3-primitives-for-arbitrary-memory-read-write-cve-2025-6554-explained-video/ Educational Purposes!

    Post summary

    The post announces CVE‑2025‑6554, explaining the Chrome V8 sandbox escape via three primitives that enable arbitrary memory read/write, and links to an educational article and video for further details.

    000001.3K
    577 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more