ZeroHour

CVE-2019-5825

KEV PoC ×2mass

Out-of-Bounds Write in Google Chrome V8 JavaScript Engine (CVE-2019-5825)

CISA: Google Chromium V8 Out-of-Bounds Write Vulnerability

CVSS 3.1
6.5 medium
EPSS
56%p99
Published
()
KEV added
AI analysis

CVE-2019-5825 is an out-of-bounds write (CWE-787) in the V8 JavaScript engine of Google Chrome/Chromium, fixed in Chrome 73.0.3683.86. A remote attacker triggers it by getting a user to open a crafted HTML page whose JavaScript writes beyond allocated memory bounds, corrupting the heap; no authentication is required, only user interaction with the malicious page. Successful exploitation yields heap corruption in the browser renderer — the CVSS-scored impact is high availability loss (crash), and V8 out-of-bounds writes of this type are a classic precursor to renderer code execution. Anyone running Google Chrome (or Chromium/V8-based builds) prior to 73.0.3683.86 — essentially the entire Chrome user base when the fix shipped in March 2019 — was affected. The flaw is now known to be exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-06-08, carries a high EPSS score (55.9%, 99th percentile), and has public PoC references (crbug 941743, Packet Storm); CISA's ransomware association is unknown.

What to do: Update Google Chrome to 73.0.3683.86 or later — any current stable Chrome build includes this fix, so verify auto-updates are functioning and inventory for legacy, pinned, or managed Chrome/Chromium installs, embedded Chromium components, or V8-based tooling still on pre-73.0.3683.86 versions. Because the flaw is on CISA's KEV list, treat it as actively exploited and prioritize remediation on user-facing and internet-exposed systems.

Affected
Google Chromeprior to 73.0.3683.86
Google Chromium V8 JavaScript engine (as bundled in Chrome)prior to 73.0.3683.86 (fixed via the Chrome 73.0.3683.86 release)
Estimated exposure
mass≈1+ billion Chrome users exposed at the March 2019 disclosure; residual count of unpatched installs today unknown — Chrome was the world's dominant browser with well over a billion active users in 2019, and every user on a pre-73.0.3683.86 build was exposed until Chrome's silent auto-updater delivered the fix, so the original exposure was effectively…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chromium V8
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
google
Products
chrome
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.