Google has issued an urgent, out-of-band security update for the Chrome Stable channel, addressing two separate Type Confusion vulnerabilities in the critical V8 JavaScript engine. The most serious of these, CVE-2025-13223, is confirmed to be a zero-day flaw that is already being actively exploited in the wild.
The vulnerability posing the most immediate threat was reported by Google’s Threat Analysis Group (TAG), which typically tracks sophisticated, targeted attacks. The flaw is tracked as CVE-2025-13223 – Type Confusion in V8.
Type Confusion vulnerabilities occur when a program incorrectly assumes the data type of an object, leading to logical errors and memory misinterpretation. In the context of the V8 engine—the heart of Chrome’s web processing—exploiting this flaw can allow attackers to achieve heap corruption, which is a common precursor to gaining arbitrary code execution (RCE).
This means an attacker could compromise a user’s system simply by convincing them to visit a specially crafted website, making this a severe, drive-by attack risk.
The company confirms, “Google is aware that an exploit for CVE-2025-13223 exists in the wild.”
The update also includes a fix for a second, separate vulnerability in the V8 engine. Tracked as CVE-2025-13224, this flaw also is Type Confusion bug.
While there is no current public confirmation of active exploitation for this second flaw, its identical classification as a High-severity Type Confusion bug in the V8 engine necessitates immediate patching.
Google is restricting access to the bug details to give the majority of users time to update and prevent wider exploitation. The patch is rolling out over the coming days/weeks, but users shouldn’t wait for the automatic update.
All users of Chrome on Windows, Mac, and Linux are strongly advised to update immediately to the new stable versions: 142.0.7444.175/.176 (Windows), 142.0.7444.176 (Mac), and 142.0.7444.175 (Linux).
To ensure you are protected against the zero-day threat, please update immediately:
- Open Google Chrome.
- Click the three-dot menu (…) in the top right corner.
- Go to Help –> About Google Chrome.
- The browser will automatically check for and download the update. You will be prompted to Relaunch to apply the fix.