ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Google fixes Chrome zero-day with in-the-wild exploit (CVE-2025-5419)

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-5419

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-5419
Actively Exploited Out-of-Bounds Read/Write in Chromium V8 (Chrome, Edge)

CVE-2025-5419 is an out-of-bounds read and write (CWE-125, CWE-787) in the V8 JavaScript engine used by Google Chromium, rated High with a CVSS 3.1 score of 8.8. A remote attacker can trigger it by persuading a user to open a crafted HTML page (network attack vector, user interaction required, no privileges needed). Successful exploitation can corrupt the V8 heap, potentially giving the attacker code execution in the context of the browser with high impact on confidentiality, integrity, and availability. Anyone running the unpatched V8 engine is affected, including Google Chrome prior to 137.0.7151.68 and Chromium-based browsers such as Microsoft Edge that ship the vulnerable engine. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-06-05, though ransomware use is not yet known.

Do: Update Google Chrome to 137.0.7151.68 or later and restart the browser to load the fixed V8 (verify the version at chrome://version); apply the corresponding Chromium 137-based security update for Microsoft Edge and confirm via edge://version. Federal agencies must apply vendor mitigations or follow BOD 22-01 cloud-service guidance per the KEV listing. Since exploitation occurs via attacker-crafted web pages, prompt patching is the primary mitigation, and no public PoC is currently known.

8.88% KEV
  • Google Chrome (V8 JavaScript engine) prior to 137.0.7151.68
  • Google Chromium V8 (component per CISA) V8 as shipped in Chrome prior to 137.0.7151.68
  • Microsoft Edge (Chromium-based) builds incorporating the unpatched V8 engine; fixed version number not stated in source data
masson the order of billions of browser users were exposed pre-patch (Chrome alone ~3B+ users at ~65% global browser share, plus hundreds of millions of Edge users)
Full article300 words · extracted from helpnetsecurity.com · click to collapse

Google has fixed two Chrome vulnerabilities, including a zero-day flaw (CVE-2025-5419) with an in-the-wild exploit.

CVE-2025-5419

About CVE-2025-5419

CVE-2025-5419 is a high-severity out of bounds read and write vulnerability in V8, the JavaScript and WebAssembly engine developed by Google for the Chromium and Chrome web browsers. It allows remote attackers to trigger heap corruption via a crafted HTML page.

It was reported by Clément Lecigne and Benoît Sevens of Google’s Threat Analysis Group – a specialized team dedicated to protecting Google users, platforms, and the broader internet from targeted and state-sponsored cyber threats – thus it’s highly likely that the vulnerability is being actively exploited by threat actors.

They reported the vulnerability on May 27 and Google mitigated the issue the following day by pushing out a configuration change to the Stable channel across all Chrome platforms.

As per usual, Google did not share details about the attacks and the exploit, and has temporarily restricted access to bug details and links to allow for most users to get the update with the fix: Chrome v137.0.7151.68 for Windows and Linux, and Chrome v137.0.7151.69 for macOS.

Implementing updates

If you’ve enabled automatic updates in Chrome, the security update has already been downloaded, you just need to restart the browser to implement it.

If you opted for updating manually, you should check for the latest update and install it quickly.

The two vulnerabilities have also been patched in the stable channel of Chromium-based Microsoft Edge.

The Brave, Opera, and Vivaldi browsers are also based on Chromium, so expect fixes for these flaws to be delivered soon.

UPDATE (June 6, 2025, 04:50 a.m. ET):

CVE-2025-5419 has been added to CISA’s Known Exploited Vulnerabilities catalog.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/06/04/google-fixes-chrome-zero-day-with-in-the-wild-exploit-cve-2025-5419/