Google released a Chrome Stable security update addressing four high-severity vulnerabilities, including CVE-2025-10585, a V8 type confusion flaw for which Google confirmed an exploit exists in the wild. Google Threat Analysis Group reported the vulnerability. The patched releases are 140.0.7339.185/.186 for Windows and Mac and 140.0.7339.185 for Linux, with a phased rollout announced on September 17, 2025.
The update also fixes two use-after-free vulnerabilities and a heap buffer overflow across Dawn, WebRTC, and ANGLE. Related Chromium tickets identify use-after-free issues in WebRTC’s MediaStreamDescriptor and Dawn’s WebGPU D3D12 resource allocator, but the available tracker content provides no further exploitation details. Google said vulnerability details may remain restricted until sufficient patch adoption. Organizations should ensure managed Chrome installations run these patched versions or newer supported releases, prioritizing remediation because of the confirmed in-the-wild V8 exploit.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
Google Threat Analysis Group reported CVE-2025-10585, a high-severity type confusion vulnerability in Chrome's V8 engine, tracked as Chromium issue 445380761.
Sherkito reported CVE-2025-10501, a high-severity use-after-free vulnerability in Chrome's WebRTC component. Google listed a $10,000 reward for the report.
Google Big Sleep reported CVE-2025-10502, a high-severity heap buffer overflow vulnerability in Chrome's ANGLE component.
Giunash (Gyujeong Jin) reported CVE-2025-10500, a high-severity use-after-free vulnerability in Chrome's Dawn component. Google listed a $15,000 reward for the report.
Google updated Chrome Stable to 140.0.7339.185/.186 for Windows and Mac and 140.0.7339.185 for Linux, fixing four high-severity vulnerabilities in V8, Dawn, WebRTC, and ANGLE. In the release notice, Google confirmed that an exploit for CVE-2025-10585 exists in the wild.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
chromereleases.googleblog.com
Open sourceissues.chromium.org
Open sourceissues.chromium.org
Open sourceissues.chromium.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.