CVE-2025-6554: Google Chromium V8 Type Confusion Vulnerability

High severity, CVSS 8.1. Actively exploited: in CISA KEV since 2025-07-02. EPSS: 14.1% chance of exploitation in the next 30 days.

Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

Affected products

  • Google Chrome: before 138.0.7204.96 (fixed in 138.0.7204.96); before 138.0.7204.92 (fixed in 138.0.7204.92)

Published 2025-06-30. Last modified 2026-06-17.