Google Chrome V8 Type Confusion Vulnerability Allowing Heap Corruption

Vulnerability

A type confusion vulnerability has been identified in the V8 JavaScript engine used by Google Chrome. This issue, present in Chrome versions prior to 138.0.7204.168, could allow a remote attacker to exploit heap corruption by crafting a malicious HTML page. The vulnerability has been rated high severity by Chromium security.

Impact

Exploitation of this vulnerability could lead to heap corruption, a common precursor to memory corruption vulnerabilities that can be exploited to execute arbitrary code.

Remediation

Users can update to Google Chrome version 138.0.7204.168 or later to address this vulnerability. The update is being rolled out gradually, with the desktop version available for Windows, Mac, and Linux.

Added: Jul 22, 2025, 10:18 PM
Updated: Jul 22, 2025, 10:18 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
4.4
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.