ZeroHour

CVE-2025-5419

KEVmass

Actively Exploited Out-of-Bounds Read/Write in Chromium V8 (Chrome, Edge)

CISA: Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

CVSS 3.1
8.8 high
EPSS
8%p94
Published
()
KEV added
AI analysis

CVE-2025-5419 is an out-of-bounds read and write (CWE-125, CWE-787) in the V8 JavaScript engine used by Google Chromium, rated High with a CVSS 3.1 score of 8.8. A remote attacker can trigger it by persuading a user to open a crafted HTML page (network attack vector, user interaction required, no privileges needed). Successful exploitation can corrupt the V8 heap, potentially giving the attacker code execution in the context of the browser with high impact on confidentiality, integrity, and availability. Anyone running the unpatched V8 engine is affected, including Google Chrome prior to 137.0.7151.68 and Chromium-based browsers such as Microsoft Edge that ship the vulnerable engine. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-06-05, though ransomware use is not yet known.

What to do: Update Google Chrome to 137.0.7151.68 or later and restart the browser to load the fixed V8 (verify the version at chrome://version); apply the corresponding Chromium 137-based security update for Microsoft Edge and confirm via edge://version. Federal agencies must apply vendor mitigations or follow BOD 22-01 cloud-service guidance per the KEV listing. Since exploitation occurs via attacker-crafted web pages, prompt patching is the primary mitigation, and no public PoC is currently known.

Affected
Google Chrome (V8 JavaScript engine)prior to 137.0.7151.68
Google Chromium V8 (component per CISA)V8 as shipped in Chrome prior to 137.0.7151.68
Microsoft Edge (Chromium-based)builds incorporating the unpatched V8 engine; fixed version number not stated in source data
Estimated exposure
masson the order of billions of browser users were exposed pre-patch (Chrome alone ~3B+ users at ~65% global browser share, plus hundreds of millions of Edge users) — Chrome's roughly two-thirds global browser market share translates to billions of installations and Microsoft Edge (also Chromium/V8-based) adds hundreds of millions more, with all users on pre-137.0.7151.68 builds vulnerable until they…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CISA Known Exploited Vulnerability
Affected
Google Chromium V8
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
googlemicrosoft
Products
chrome, edge chromium
Weakness
CWE-125, CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news