Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
HighCISA KEVExploited in the wildPublic exploit

Type Confusion in Google Chrome V8

IdentifiersCVE-2025-13223CWE-843· Access of Resource Using…

CVE-2025-13223 is a high-severity type confusion vulnerability in the V8 JavaScript engine used by Google Chrome, including references indicating impact in the JavaScript and WebAssembly engine. In Google Chrome versions prior to 142.0.7444.175, processing a crafted HTML page can trigger type confusion that leads to heap corruption. Multiple sources in the provided content state that Google confirmed exploitation in the wild and that the issue was reported by Google Threat Analysis Group (TAG).

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation can cause heap corruption, browser crashes, and potentially arbitrary code execution in the context of the Chrome renderer or logged-in user. The provided content further indicates that, when chained with additional vulnerabilities such as sandbox escape or privilege-escalation bugs, the flaw could contribute to full system compromise and has been associated in reporting with spyware and nation-state espionage operations.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, reduce exposure by restricting or isolating web browsing to untrusted sites, using browser isolation or other layered web controls, enforcing least privilege so browser compromise does not yield administrative access, and applying URL/DNS filtering and anti-exploitation protections. However, the content indicates no vendor workaround; patching and browser restart are the primary mitigations.

Remediation

Patch, then assume compromise.

Update Google Chrome to a fixed version. The provided content states affected versions are prior to 142.0.7444.175 on Linux and prior to 142.0.7444.175/.176 on Windows and macOS; organizations should deploy the vendor-fixed Chrome 142 builds or later across all platforms and ensure browsers are restarted so the update is actually applied. Apply corresponding updates to Chromium-based downstream browsers as they become available.
PUBLIC EXPLOITS

Exploits

1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.

VALID 1 / 1 TOTALView more in app
CVE-2025-13223MaturityPoCVerified exploit

This repository provides a proof-of-concept exploit for CVE-2025-13223, a critical type confusion vulnerability in the V8 JavaScript engine of Google Chrome (up to version 141.0.7390.76 on Windows). The exploit is designed to demonstrate heap corruption and arbitrary read/write in the Chrome renderer process by generating a malicious HTML file (payload.html) with JavaScript that manipulates TypedArray objects and prototype chains. The exploit is executed via a Windows executable (exploit.exe, included in a downloadable ZIP), which prepares the payload and guides the user to load it in a vulnerable Chrome instance. The repository includes a configuration file (config.json) to adjust exploit parameters such as heap spray size and prototype chain depth. The attack vector is browser-based, requiring the victim to visit a crafted page, and is remote-capable but requires user interaction. The repository is structured with a detailed README.md explaining usage, prerequisites, and mitigation, and a config.json for exploit tuning. No source code for the exploit executable or payload is included in the repository itself, but the documentation is comprehensive and outlines the exploit's operation and intended research use.

Darwin72820Disclosed Nov 25, 2025jsonbrowsernetwork
EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
GoogleChromeapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures2

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity105

Community discussion across Reddit, Mastodon, and other social sources.