Google Chrome Type Confusion Vulnerability (CVE-2025-0291)
CVSS SCORE: 8.3 High
BACKGROUND
CVE-2025-0291 is a high-severity vulnerability identified in Google Chrome's V8 JavaScript engine that can lead to remote code execution. This vulnerability stems from a Type Confusion flaw, where the program incorrectly treats data as a different type than intended. Such flaws can allow attackers to manipulate memory, potentially resulting in data theft, system crashes, or full device takeover.
IMPACT
• Allow attackers to run arbitrary code on a user's system.
• Potentially leads to data theft, system compromise, or further attacks by taking over the affected device.
AFFECTED PRODUCTS
• Google Chrome web browser versions prior to 131.0.6778.264 across all platforms (Windows, Mac and Linux) except iOS.
RECOMMENDATIONS
Users are advised to immediately update their Chrome browsers to the latest version:
- For Windows and Mac: update to stable channel versions prior to 131.0.6778.264/.265.
For Linux: update to versions prior to 131.0.6778.264.
REFERENCES
https://nvd.nist.gov/vuln/detail/CVE-2025-0291https://securityonline.info/chrome-update-addresses-high-severity-vulnerability-cve-2025-0291/
https://chromereleases.googleblog.com/2025/01/stable-channel-update-for-desktop.html