Vulnerability record · CVE-2019-5825 · published 25 November 2019
CVE-2019-5825: Google Chrome JavaScript out-of-bounds write enables heap corruption
Google · Chrome
Google Chrome before 73.0.3683.86 contains an out-of-bounds write in its JavaScript engine. A crafted HTML page can trigger the write and corrupt heap memory. The flaw is remotely reachable and has been exploited in the wild, so unpatched browsers are a real risk.
Description
Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Automated analysis
high priorityThe flaw is remotely reachable, has public exploit references, and is in CISA KEV with high EPSS, though it requires user interaction and only availability impact is scored.
What it is
Google Chrome before 73.0.3683.86 contains an out-of-bounds write in its JavaScript engine. A crafted HTML page can trigger the write and corrupt heap memory. The flaw is remotely reachable and has been exploited in the wild, so unpatched browsers are a real risk.
Impact
An attacker can corrupt heap memory through a malicious page, which can lead to code execution or a browser crash. The CVSS vector rates only availability impact, but the out-of-bounds write class and public exploit references indicate memory corruption that can be chained further.
Attack surface
Reached over the network by loading a crafted HTML page in Chrome; no authentication is required, but the victim must open or be directed to the page (UI:R). The attack is client-side and depends on the browser rendering the malicious content.
Exploitation
CVE-2019-5825 is listed in CISA KEV with a 2022-06-08 addition date, and public exploit references exist (Packet Storm, crbug). EPSS is 0.55925 (99th percentile), indicating high predicted exploitation activity.
What to do
- Update Google Chrome to 73.0.3683.86 or later, and apply the vendor's stable channel update.
- Enforce automatic browser updates and verify version compliance across endpoints.
- Restrict or block untrusted web content and use network controls where feasible.
- Monitor CISA KEV guidance and apply required actions by the stated due date.
Detection
- Hunt for Chrome versions below 73.0.3683.86 in asset inventories and endpoint telemetry.
- Monitor for browser crashes or renderer process terminations that may indicate heap corruption attempts.
- Review proxy and DNS logs for access to known exploit-hosting or malformed-page delivery domains.
- Correlate endpoint process creation of chrome.exe with suspicious child processes or memory anomalies.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-5825 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "Google Chromium V8 Out-of-Bounds Write Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 22 June 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/156641/Google-Chrome-72-73-Array.map-Corruption.html | ExploitThird Party AdvisoryVDB Entry |
| https://chromereleases.googleblog.com/2019/04/stable-channel-update-for-desktop_30.html | Release NotesVendor Advisory |
| https://crbug.com/941743 | ExploitPatchThird Party Advisory |
| http://packetstormsecurity.com/files/156641/Google-Chrome-72-73-Array.map-Corruption.html | ExploitThird Party AdvisoryVDB Entry |
| https://chromereleases.googleblog.com/2019/04/stable-channel-update-for-desktop_30.html | Release NotesVendor Advisory |
| https://crbug.com/941743 | ExploitPatchThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-5825 | US Government Resource |
Track CVE-2019-5825 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-5825), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.