Google Patches Chrome Zero-Day CVE-2025-10585 as Active V8 Exploit Threatens Millions
Google released security updates for Chrome to fix four vulnerabilities, including an actively exploited zero-day, CVE-2025-10585 — a type-confusion bug in the V8 JavaScript / WebAssembly engine that can lead to arbitrary code execution when a user visits a crafted webpage. Google’s Threat Analysis Group (TAG) reported the flaw on 16 September 2025 and confirmed an exploit exists in the wild. Technical details have been withheld to limit further abuse.