CVE-2025-10585
KEV Critical · CVSS 9.8Google Chrome V8 JavaScript Engine — Type confusion heap corruption RCE
- CVSS
- 9.8
- nvd
- EPSS
- 5.42%
- 92th pct
- KEV
- Listed
- 2025-09-23
- Class
- oss containerizable
- CWE-843, CWE-843
Description
Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Search profile — drives PoC discovery
Symbols V8TypeConfusionheap corruptioncrafted HTML pageissues.chromium.org/issues/445380761CVE-2025-10585
Keywords CVE-2025-10585V8 type confusionChrome 140 exploitChrome heap corruption PoCV8 exploit 2025Chromium 445380761Chrome 140.0.7339.185 vulnerabilityV8 CWE-843
Versions: prior to 140.0.7339.185
Ranked PoCs (14) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
- ★ 13gh_search
- ★ 00xAtef/0xAtef needs reviewtrickest
- ★ 0CryptoGenNepal/CVE-KEV-RSS needs reviewtrickest
- ★ 0DevGreick/devgreick needs reviewtrickest
- ★ 0PuddinCat/GithubRepoSpider needs reviewtrickest
- ★ 0callinston/CVE-2025-10585 needs reviewtrickest
- ★ 0dan-mba/python-selenium-news needs reviewtrickest
- ★ 0defronixpro/Defronix-Cybersecurity-Roadmap needs reviewtrickest
- ★ 0frlc/frlc needs reviewtrickest
- ★ 0samus4vic/CVE-2025-10585-The-Chrome-V8-Zero-Day needs reviewtrickest
- ★ 0thexnumb/thexwriteup needs reviewtrickest
- ★ 0w4zu/Debian_security needs reviewtrickest
- ★ 0wjlin0/wjlin0 needs reviewtrickest
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-14T18:30:20.000Z