CVE-2025-6554 is a high-severity type confusion vulnerability in Google Chrome's V8 engine, affecting Google, Apple, Linux, and Microsoft products. It allows a remote attacker to achieve arbitrary read/write capabilities by enticing a user to visit a crafted HTML page. With a CVSS score of 8.1, the vulnerability is easily exploitable over a network with low complexity, potentially leading to significant confidentiality and integrity impacts. This flaw is actively exploited in the wild, as confirmed by its presence in the KEV catalog, and has garnered substantial community discussion and media coverage, despite the lack of public exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 138.0.7204.96, < 138.0.7204.96CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 138.0.7204.96CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 138.0.7204.92CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.