Vulnerability record · CVE-2025-13223 · published 17 November 2025
CVE-2025-13223: Google Chrome V8 type confusion allows heap corruption
Google · Chrome
Google Chrome before 142.0.7444.175 contains a type confusion flaw in the V8 JavaScript engine. A crafted HTML page can trigger the confusion and potentially corrupt the heap, which matters because Chrome is widely deployed and the flaw is remotely reachable.
Description
Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote, unauthenticated-reachable type confusion in a widely used browser with high CVSS impact and confirmed KEV exploitation, though it requires user interaction.
What it is
Google Chrome before 142.0.7444.175 contains a type confusion flaw in the V8 JavaScript engine. A crafted HTML page can trigger the confusion and potentially corrupt the heap, which matters because Chrome is widely deployed and the flaw is remotely reachable.
Impact
An attacker who gets the page rendered may achieve heap corruption, which can lead to code execution or a crash in the browser process. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reached over the network by a crafted HTML page; the CVSS vector requires user interaction (UI:R) and no privileges (PR:N), so a victim must open or be lured to the page. No authentication is needed.
Exploitation
CVE-2025-13223 was added to CISA KEV on 2025-11-19, indicating known exploitation, though the record does not state whether it is used in ransomware. EPSS gives a 30-day probability of about 5.0 percent (91.8th percentile).
What to do
- Update Google Chrome to 142.0.7444.175 or later, and apply the vendor advisory for any affected Siemens CADRA deployment.
- Follow CISA KEV required action and BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable.
- Enforce automatic browser updates and verify version compliance across managed endpoints.
- Restrict or isolate browsing of untrusted web content where operationally feasible.
Detection
- Monitor for Chrome renderer crashes or abnormal process terminations that could indicate heap corruption attempts.
- Hunt for exploitation attempts against V8 using endpoint detection rules or browser exploit telemetry.
- Track Chrome version inventory to find endpoints still below 142.0.7444.175.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-13223 to the Known Exploited Vulnerabilities catalog on 19 November 2025 as "Google Chromium V8 Type Confusion Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 10 December 2025.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://chromereleases.googleblog.com/2025/11/stable-channel-update-for-desktop_17.html | Release NotesVendor Advisory |
| https://issues.chromium.org/issues/460017370 | Issue TrackingPermissions Required |
| https://cert-portal.siemens.com/productcert/html/ssa-470355.html | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-13223 | US Government Resource |
Track CVE-2025-13223 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-13223), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.