A high-severity vulnerability, tracked as CVE-2025-13042, was identified in the V8 JavaScript engine of Google Chrome, allowing remote attackers to exploit heap corruption through specially crafted HTML pages. This flaw could enable remote code execution on affected systems, posing significant risks to users who visit malicious websites. Google released an emergency fix to address the issue, urging users to update their browsers immediately to mitigate potential exploitation.
The vulnerability affects Google Chrome versions prior to 142.0.7444.166, and its severity is underscored by a CVSS score of 8.8. Security advisories highlight that the flaw is remotely exploitable and could be leveraged by attackers to gain control over vulnerable systems. Organizations are advised to prioritize patching and monitor for any signs of exploitation in their environments.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Public vulnerability tracking for CVE-2025-13042 described the issue as a Google Chrome heap corruption flaw affecting the V8 engine. This made the vulnerability details broadly available through CVE tracking sources on November 12, 2025.
Google released an emergency fix for the high-severity Chrome V8 heap corruption vulnerability tracked as CVE-2025-13042, which could allow remote code execution. The references indicate the issue was publicly disclosed as a Chrome security update on November 12, 2025.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.