Google released security updates for Chrome for Desktop to address several high-severity vulnerabilities, including flaws in the V8 JavaScript engine. One of the vulnerabilities, CVE-2025-10585, was added to CISA's Known Exploited Vulnerabilities (KEV) catalog after a public exploit became available. Security advisories from both Google and government agencies urged users and administrators to update Chrome to the latest versions to mitigate the risk of exploitation. The patched vulnerabilities affect Chrome versions prior to 140.0.7339.207/.208 on Windows and Mac, and 140.0.7339.207 on Linux.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published advisory AV25-615 covering the Google Chrome vulnerabilities and associated security updates. The advisory reinforced patching guidance for affected users and organizations.
CISA added Chrome zero-day CVE-2025-10585 to its KEV catalog after reports of a public exploit. This designation signaled active exploitation risk and urged organizations to prioritize remediation.
A public exploit for Chrome zero-day CVE-2025-10585 became available, elevating the urgency of the vulnerability and prompting government attention. The exact publication date is not specified in the references, but it was known by September 24, 2025.
Google issued Chrome security updates addressing three high-severity vulnerabilities in the V8 JavaScript engine, including CVE-2025-10585. The fixes were published as part of Chrome's September 24, 2025 security update cycle.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcesecurityonline.info
Open sourcecyber.gc.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.