CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-10585

KEV Critical · CVSS 9.8

Google Chrome V8 JavaScript Engine — Type confusion heap corruption RCE

CVSS
9.8
nvd
EPSS
5.42%
92th pct
KEV
Listed
2025-09-23
Class
oss containerizable
CWE-843, CWE-843

Description

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Search profile — drives PoC discovery

Symbols V8TypeConfusionheap corruptioncrafted HTML pageissues.chromium.org/issues/445380761CVE-2025-10585
Keywords CVE-2025-10585V8 type confusionChrome 140 exploitChrome heap corruption PoCV8 exploit 2025Chromium 445380761Chrome 140.0.7339.185 vulnerabilityV8 CWE-843
Versions: prior to 140.0.7339.185

Ranked PoCs (14) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-14T18:30:20.000Z