cbcvebase.
CVE-2025-5419
published 2025-06-03

CVE-2025-5419: Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…

PriorityP184high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2025-06-26
Exploited in the wild
EPSS
6.45%
93.0th percentile
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Affected

10 ranges
VendorProductVersion rangeFixed in
chromiumchromium>= 0 < 137.0.7151.68-1~deb12u1137.0.7151.68-1~deb12u1
chromiumchromium>= 0 < 137.0.7151.68-1137.0.7151.68-1
chromiumchromium>= 0 < 137.0.7151.68-1137.0.7151.68-1
debianchromium< chromium 137.0.7151.68-1~deb12u1 (bookworm)chromium 137.0.7151.68-1~deb12u1 (bookworm)
googlechrome< 137.0.7151.68137.0.7151.68
googlechrome>= 137.0.7151.68 < 137.0.7151.68137.0.7151.68
googlechrome_chrome
microsoftedge_chromium< 137.0.3296.62137.0.3296.62
msrcmicrosoft_edge
paloaltoprisma_browser

Detection & IOCsextracted from sources · hover to see the quote

version137.0.7151.68
  • CVE-2025-5419 is an out-of-bounds read and write in the V8 JavaScript and WebAssembly engine, exploitable via a crafted HTML page delivered remotely — monitor for suspicious/malicious HTML page delivery targeting Chrome/Chromium-based browsers prior to version 137.0.7151.68.
  • Google TAG (Threat Analysis Group) reported this vulnerability, suggesting exploitation may be linked to government-sponsored threat actors in targeted campaigns — prioritize monitoring of high-risk individuals and organizations.
  • The vulnerability affects multiple Chromium-based browsers beyond Chrome — extend detection and patching scope to Microsoft Edge and Opera as well.
  • Google mitigated CVE-2025-5419 one day after discovery via a server-side configuration change pushed to the Stable channel before the binary patch — this suggests a V8 JIT or flag-based mitigation path worth investigating for detection bypass scenarios.
  • Active in-the-wild exploitation confirmed by Google prior to patch release — treat any unpatched Chromium-based browser (pre-137.0.7151.68) as actively at risk and flag in asset inventory.
  • ·CISA mandates remediation by 2025-06-26 under BOD 22-01 for cloud services; organizations unable to patch should discontinue use of affected Chromium-based products.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.