Vulnerability record · CVE-2025-5419 · published 3 June 2025
CVE-2025-5419: Google Chrome V8 out-of-bounds read and write enables heap corruption
Google · Chrome
V8 in Google Chrome before 137.0.7151.68 contains an out-of-bounds read and write that a remote attacker can trigger with a crafted HTML page, leading to heap corruption. The flaw is rated High by Chromium and carries a CVSS 3.1 base score of 8.8, and it affects both Chrome and Chromium-based Microsoft Edge.
Description
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with confirmed in-the-wild exploitation per CISA KEV and a short remediation deadline, though it requires user interaction and no ransomware use is documented.
What it is
V8 in Google Chrome before 137.0.7151.68 contains an out-of-bounds read and write that a remote attacker can trigger with a crafted HTML page, leading to heap corruption. The flaw is rated High by Chromium and carries a CVSS 3.1 base score of 8.8, and it affects both Chrome and Chromium-based Microsoft Edge.
Impact
An attacker who lands the corruption can potentially achieve code execution or crash the renderer in the browser process context, giving high confidentiality, integrity and availability impact.
Attack surface
Reached over the network by loading a crafted HTML page; no privileges are required but the victim must interact with the page (UI:R), so it is a drive-by or lure-based browser attack.
Exploitation
CVE-2025-5419 was added to CISA KEV on 2025-06-05 with a 2025-06-26 remediation due date, indicating known exploitation in the wild; EPSS 30-day probability is 0.078 (94th percentile). No ransomware campaign use is documented.
What to do
- Update Google Chrome to 137.0.7151.68 or later and Microsoft Edge to the corresponding fixed Chromium build immediately.
- Apply vendor mitigations per CISA BOD 22-01 guidance for cloud services, or discontinue use of unpatched browsers.
- Enforce automatic browser updates and verify version compliance across endpoints.
- Restrict or sandbox untrusted web content and block known malicious domains where feasible.
- Monitor for exploitation attempts against exposed browser users and prioritize patching internet-facing endpoints.
Detection
- Hunt for browser crashes or renderer process terminations consistent with V8 heap corruption on endpoints running Chrome below 137.0.7151.68.
- Review proxy, DNS and EDR telemetry for delivery of crafted HTML pages or exploit kit activity targeting browser users.
- Audit asset inventories for Chrome and Edge versions and flag any host not on the fixed Chromium build.
- Correlate CISA KEV due-date compliance reporting with endpoint patch status for CVE-2025-5419.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-5419 to the Known Exploited Vulnerabilities catalog on 5 June 2025 as "Google Chromium V8 Out-of-Bounds Read and Write Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 26 June 2025.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop.html | Release Notes |
| https://issues.chromium.org/issues/420636529 | Permissions Required |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-5419 | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-5419 | US Government Resource |
Track CVE-2025-5419 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-5419), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.