Home/CVEs/CVE-2025-6554/

CVE-2025-6554 - Google Chromium V8 Type Confusion Vulnerability

Project:Google

Product:Chromium V8

Date Added:2025-07-02Due Date:2025-07-23

Vulnerability Name

Google Chromium V8 Type Confusion Vulnerability

Description

Google Chromium V8 contains a type confusion vulnerability that could allow a remote attacker to perform arbitrary read/write via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Known To Be Used in Ransomware Campaigns?

Unknown

Action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Additional Notes

https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_30.html?m=1

https://nvd.nist.gov/vuln/detail/CVE-2025-6554

Related News Articles

Google Patches Chrome Zero-Day CVE-2025-10585 as Active V8 Exploit Threatens MillionsSeptember 18, 2025

Urgent: Google Releases Critical Chrome Update for CVE-2025-6558 Exploit Active in the WildJuly 16, 2025

Google fixes actively exploited sandbox escape zero day in ChromeJuly 16, 2025

Microsoft July 2025 Patch Tuesday fixes one zero-day, 137 flawsJuly 9, 2025

Grafana releases critical security update for Image Renderer pluginJuly 4, 2025