This vulnerability is known to have been exploited in attacks. Update affected browsers immediately.
CVE details
CVE-2025-6554
Type confusion in V8 in Google Chrome prior to 138.
Description
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
Affected products
- Google Chrome · → 138.0.7204.96
- Google Chrome · → 138.0.7204.92
- Chromium · → 138.0.7204.96
Overlaps: Google Chrome, Chromium