Skip to main content

Google Chrome Type Confusion Vulnerability (CVE-2025-0291)

CVSS SCORE: 8.3 High

BACKGROUND

CVE-2025-0291 is a high-severity vulnerability identified in Google Chrome's V8 JavaScript engine that can lead to remote code execution. This vulnerability stems from a Type Confusion flaw, where the program incorrectly treats data as a different type than intended. Such flaws can allow attackers to manipulate memory, potentially resulting in data theft, system crashes, or full device takeover.        

IMPACT

•     Allow attackers to run arbitrary code on a user's system. 
•      Potentially leads to data theft, system compromise, or further attacks by taking over the affected device.
 

AFFECTED PRODUCTS


•      Google Chrome web browser versions prior to 131.0.6778.264 across all platforms (Windows, Mac and Linux) except iOS.
 

RECOMMENDATIONS

Users are advised to immediately update their Chrome browsers to the latest version:

About

Brunei Computer Emergency Response Team (BruCERT) was established in 2004 as the national and government CERT to deal with computer-related and internet-related security incidents in Negara Brunei Darussalam.