CVE-2019-5825
KEV PoC ×2massOut-of-Bounds Write in Google Chrome V8 JavaScript Engine (CVE-2019-5825)
CISA: Google Chromium V8 Out-of-Bounds Write Vulnerability
CVE-2019-5825 is an out-of-bounds write (CWE-787) in the V8 JavaScript engine of Google Chrome/Chromium, fixed in Chrome 73.0.3683.86. A remote attacker triggers it by getting a user to open a crafted HTML page whose JavaScript writes beyond allocated memory bounds, corrupting the heap; no authentication is required, only user interaction with the malicious page. Successful exploitation yields heap corruption in the browser renderer — the CVSS-scored impact is high availability loss (crash), and V8 out-of-bounds writes of this type are a classic precursor to renderer code execution. Anyone running Google Chrome (or Chromium/V8-based builds) prior to 73.0.3683.86 — essentially the entire Chrome user base when the fix shipped in March 2019 — was affected. The flaw is now known to be exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-06-08, carries a high EPSS score (55.9%, 99th percentile), and has public PoC references (crbug 941743, Packet Storm); CISA's ransomware association is unknown.
What to do: Update Google Chrome to 73.0.3683.86 or later — any current stable Chrome build includes this fix, so verify auto-updates are functioning and inventory for legacy, pinned, or managed Chrome/Chromium installs, embedded Chromium components, or V8-based tooling still on pre-73.0.3683.86 versions. Because the flaw is on CISA's KEV list, treat it as actively exploited and prioritize remediation on user-facing and internet-exposed systems.
| Google Chrome | prior to 73.0.3683.86 |
| Google Chromium V8 JavaScript engine (as bundled in Chrome) | prior to 73.0.3683.86 (fixed via the Chrome 73.0.3683.86 release) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- Affected
- Google Chromium V8
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Products
- chrome
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.