CVE-2025-5419
published 2025-06-03CVE-2025-5419: Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…
PriorityP184high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2025-06-26
Exploited in the wild
EPSS
6.45%
93.0th percentile
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 137.0.7151.68-1~deb12u1 | 137.0.7151.68-1~deb12u1 |
| chromium | chromium | >= 0 < 137.0.7151.68-1 | 137.0.7151.68-1 |
| chromium | chromium | >= 0 < 137.0.7151.68-1 | 137.0.7151.68-1 |
| debian | chromium | < chromium 137.0.7151.68-1~deb12u1 (bookworm) | chromium 137.0.7151.68-1~deb12u1 (bookworm) |
| chrome | < 137.0.7151.68 | 137.0.7151.68 | |
| chrome | >= 137.0.7151.68 < 137.0.7151.68 | 137.0.7151.68 | |
| chrome_chrome | — | — | |
| microsoft | edge_chromium | < 137.0.3296.62 | 137.0.3296.62 |
| msrc | microsoft_edge | — | — |
| paloalto | prisma_browser | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2025-5419 is an out-of-bounds read and write in the V8 JavaScript and WebAssembly engine, exploitable via a crafted HTML page delivered remotely — monitor for suspicious/malicious HTML page delivery targeting Chrome/Chromium-based browsers prior to version 137.0.7151.68. ↗
- →Google TAG (Threat Analysis Group) reported this vulnerability, suggesting exploitation may be linked to government-sponsored threat actors in targeted campaigns — prioritize monitoring of high-risk individuals and organizations. ↗
- →The vulnerability affects multiple Chromium-based browsers beyond Chrome — extend detection and patching scope to Microsoft Edge and Opera as well. ↗
- →Google mitigated CVE-2025-5419 one day after discovery via a server-side configuration change pushed to the Stable channel before the binary patch — this suggests a V8 JIT or flag-based mitigation path worth investigating for detection bypass scenarios. ↗
- →Active in-the-wild exploitation confirmed by Google prior to patch release — treat any unpatched Chromium-based browser (pre-137.0.7151.68) as actively at risk and flag in asset inventory. ↗
- ·CISA mandates remediation by 2025-06-26 under BOD 22-01 for cloud services; organizations unable to patch should discontinue use of affected Chromium-based products. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-5419: Out of bounds read and write in V8 in Google Chrome prior to 137
osv·2025-06-03·CVSS 8.8
CVE-2025-5419 [HIGH] CVE-2025-5419: Out of bounds read and write in V8 in Google Chrome prior to 137
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
GHSA
GHSA-x828-wp24-7h9m: Out of bounds read and write in V8 in Google Chrome prior to 137
ghsa_unreviewed·2025-06-03
CVE-2025-5419 [HIGH] CWE-125 GHSA-x828-wp24-7h9m: Out of bounds read and write in V8 in Google Chrome prior to 137
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
VulnCheck
Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
vulncheck·2025·CVSS 8.8
CVE-2025-5419 [HIGH] CWE-125 Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
Google Chromium V8 contains an out-of-bounds read and write vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Affected: Google Chromium V8
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop.html; https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit
Palo Alto
PAN-SA-2025-0011 Chromium and Prisma Browser: Monthly Vulnerability Update (June 2025)
vendor_paloalto·2025-06-11·CVSS 5.1
[MEDIUM] PAN-SA-2025-0011 Chromium and Prisma Browser: Monthly Vulnerability Update (June 2025)
PAN-SA-2025-0011 Chromium and Prisma Browser: Monthly Vulnerability Update (June 2025)
Palo Alto Networks incorporated the following Chromium security fixes into our products: https://chromereleases.googleblog.com/2025/06/extended-stable-updates-for-desktop.html https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop.html https://chromereleases.googleblog.com/2025/05/extended-stable-updates-for-desktop.html https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop_27.html https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop_14.html Additionally, a vulnerability in Prisma Browser was also addressed. CVE Summary CVE-2025-4664 Insufficient policy enforcement in Loader CVE-2025-5063 Use after free in Compositing CVE-2025
Microsoft
Chromium: CVE-2025-5419 Out of bounds read and write in V8
vendor_msrc·2025-06-10·CVSS 8.8
CVE-2025-5419 [HIGH] Chromium: CVE-2025-5419 Out of bounds read and write in V8
Chromium: CVE-2025-5419 Out of bounds read and write in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. Google is aware that an exploit for CVE-2025-5419 exists in the wild.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
137.0.3296.62
6/3/2025
137.0.7151.68/.69
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromiu
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2025-5419
vendor_chrome·2025-06-06·CVSS 8.8
CVE-2025-5419 [HIGH] Long Term Support Channel Update for ChromeOS: CVE-2025-5419
Long Term Support Channel Update for ChromeOS
CVE-2025-5419
CISA
Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
cisa·2025-06-05·CVSS 8.8
CVE-2025-5419 [HIGH] CWE-125 Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
Vulnerability: Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
Affected: Google Chromium V8
Google Chromium V8 contains an out-of-bounds read and write vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop.html; https://nvd.nist.gov/vuln/detail/CVE-2025-5419",
Remediation Due Date: 2025-06-26
Debian
CVE-2025-5419: chromium - Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allow...
vendor_debian·2025·CVSS 8.8
CVE-2025-5419 [HIGH] CVE-2025-5419: chromium - Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allow...
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 137.0.7151.68-1~deb12u1)
bullseye: open
forky: resolved (fixed in 137.0.7151.68-1)
sid: resolved (fixed in 137.0.7151.68-1)
trixie: resolved (fixed in 137.0.7151.68-1)
No detection rules found.
No public exploits indexed.
Mandiant
Look What You Made Us Patch: 2025 Zero-Days in Review
blogs_mandiant·2026-03-05
Look What You Made Us Patch: 2025 Zero-Days in Review
Threat Intelligence
# Look What You Made Us Patch: 2025 Zero-Days in Review
March 5, 2026
##### Google Threat Intelligence Group
##### Google Threat Intelligence
Visibility and context on the threats that matter most.
Contact Us & Get a Demo
Written by: Casey Charrier, James Sadowski, Zander Work, Clement Lecigne, Benoît Sevens, Fred Plan
### Executive Summary
Google Threat Intelligence Group (GTIG) tracked 90 zero-day vulnerabilities exploited in-the-wild in 2025. Although that volume of zero-days is lower than the record high observed in 2023 (100), it is higher than 2024’s count (78) and remained within the 60–100 range established over the previous four years, indicating a trend toward stabilization at these levels.
In 2025, we continued to observe the structural shift, first
Mandiant
Look What You Made Us Patch: 2025 Zero-Days in Review
blogs_mandiant·2026-03-05
Look What You Made Us Patch: 2025 Zero-Days in Review
## Look What You Made Us Patch: 2025 Zero-Days in Review
## Google Threat Intelligence Group
## Google Threat Intelligence
Visibility and context on the threats that matter most.
Written by: Casey Charrier, James Sadowski, Zander Work, Clement Lecigne, Benoît Sevens, Fred Plan
## Executive Summary
Google Threat Intelligence Group (GTIG) tracked 90 zero-day vulnerabilities exploited in-the-wild in 2025. Although that volume of zero-days is lower than the record high observed in 2023 (100), it is higher than 2024’s count (78) and remained within the 60–100 range established over the previous four years, indicating a trend toward stabilization at these levels.
In 2025, we continued to observe the structural shift, first identified in 2024, toward increased enterprise exploitation. Both
Bleepingcomputer
Google fixes eighth Chrome zero-day exploited in attacks in 2025
blogs_bleepingcomputer·2025-12-11·CVSS 9.8
[CRITICAL] Google fixes eighth Chrome zero-day exploited in attacks in 2025
## Google fixes eighth Chrome zero-day exploited in attacks in 2025
## Sergiu Gatlan
The company has now fixed this high-severity vulnerability for users in the Stable Desktop channel, with new versions rolling out worldwide to Windows (143.0.7499.109), macOS (143.0.7499.110), and Linux users (143.0.7499.109).
While the security patch could take days or weeks to reach all users, according to Google, it was immediately available when BleepingComputer checked for updates earlier today.
If you prefer not to update manually, you can also let your web browser check for updates automatically and install them after the next launch.
Although Google didn't share any other details about this zero-day bug, including the CVE ID used to track it, and said it's still "under coordination."
"Access
Bleepingcomputer
Google fixes new Chrome zero-day flaw exploited in attacks
blogs_bleepingcomputer·2025-11-18·CVSS 9.8
[CRITICAL] Google fixes new Chrome zero-day flaw exploited in attacks
## Google fixes new Chrome zero-day flaw exploited in attacks
## Sergiu Gatlan
Google fixed the zero-day flaw with the release of 142.0.7444.175/.176 for Windows, 142.0.7444.176 for Mac, and 142.0.7444.175 for Linux.
While these new versions are scheduled to roll out to all users in the Stable Desktop channel over the coming weeks, the patch was immediately available when BleepingComputer checked for the latest updates.
Although the Chrome web browser updates automatically when security patches are available, users can also confirm they're running the latest version by going to Chrome menu > Help > About Google Chrome, letting the update finish, and then clicking on the 'Relaunch' button to install it.
Although Google has already confirmed that CVE-2025-13223 was used in attacks, i
Qualys
Patch Automation for Browsers with TruRisk™ Eliminate
blogs_qualys·2025-09-24·CVSS 9.8
CVE-2025-10585 [CRITICAL] Patch Automation for Browsers with TruRisk™ Eliminate
## Table of Contents
Conclusion: Automated Patching is the Smarter Way
Recently, CISA added a Chrome zero-day vulnerability, CVE-2025-10585 , to its Known Exploited Vulnerabilities (KEV) Catalog , confirming that threat actors are actively exploiting this high-severity flaw in real-world attacks.
This vulnerability affects multiple web browsers that utilize the Chromium engine, including Google Chrome, Microsoft Edge, Opera, and Brave.
CISA strongly urges all organizations and individual users to prioritize updating their browsers as part of essential vulnerability management practices.
A patch is available. You can find the vulnerability in Qualys VMDR and eliminate the risk as follows:
Find the vulnerability in VMDR
View Risk Elimination
Create Remediation job
We just launched a
Qualys
Automated Browser Patching with Qualys TruRisk™ Eliminate | Qualys
blogs_qualys·2025-09-24·CVSS 9.8
CVE-2025-10585 [CRITICAL] Automated Browser Patching with Qualys TruRisk™ Eliminate | Qualys
#### Table of Contents
- Conclusion: Automated Patching is the Smarter Way
Recently, CISA added a Chrome zero-day vulnerability, CVE-2025-10585, to its Known Exploited Vulnerabilities (KEV) Catalog, confirming that threat actors are actively exploiting this high-severity flaw in real-world attacks.
This vulnerability affects multiple web browsers that utilize the Chromium engine, including Google Chrome, Microsoft Edge, Opera, and Brave.
CISA strongly urges all organizations and individual users to prioritize updating their browsers as part of essential vulnerability management practices.
A patch is available. You can find the vulnerability in Qualys VMDR and eliminate the risk as follows:
- Find the vulnerability in VMDR
- View Risk Elimination
- Create Remediation job
We just laun
Bleepingcomputer
Google patches sixth Chrome zero-day exploited in attacks this year
blogs_bleepingcomputer·2025-09-18·CVSS 9.8
[CRITICAL] Google patches sixth Chrome zero-day exploited in attacks this year
## Google patches sixth Chrome zero-day exploited in attacks this year
## Sergiu Gatlan
Google has released emergency security updates to patch a Chrome zero-day vulnerability, the sixth one tagged as exploited in attacks since the start of the year.
While it didn't specifically say whether this security flaw is still being actively abused in the wild, the company warned that it has a public exploit, a common indicator of active exploitation.
"Google is aware that an exploit for CVE-2025-10585 exists in the wild," Google warned in a security advisory published on Wednesday.
This high-severity zero-day vulnerability is caused by a type confusion weakness in the web browser's V8 JavaScript engine, reported by Google's Threat Analysis Group on Tuesday.
Google TAG frequently flags zero-d
Bleepingcomputer
Google fixes actively exploited sandbox escape zero day in Chrome
blogs_bleepingcomputer·2025-07-16·CVSS 8.8
[HIGH] Google fixes actively exploited sandbox escape zero day in Chrome
## Google fixes actively exploited sandbox escape zero day in Chrome
## Bill Toulas
ANGLE (Almost Native Graphics Layer Engine) is an open-source graphics abstraction layer used by Chrome to translate OpenGL ES API calls to Direct3D, Metal, Vulkan, and OpenGL.
Because ANGLE processes GPU commands from untrusted sources like websites using WebGL, bugs in this component can have a critical security impact.
The vulnerability allows a remote attacker using a specially crafted HTML page to execute arbitrary code within the browser’s GPU process. Google has not provided the technical details on how triggering the issue could lead to escaping the browser's sandbox.
“Access to bug details and links may be kept restricted until a majority of users are updated with a fix,” states Google in the
Krebs
Patch Tuesday, June 2025 Edition
blogs_krebs·2025-06-11·CVSS 8.8
CVE-2025-33053 [HIGH] Patch Tuesday, June 2025 Edition
Microsoft today released security updates to fix at least 67 vulnerabilities in its Windows operating systems and software. Redmond warns that one of the flaws is already under active attack, and that software blueprints showing how to exploit a pervasive Windows bug patched this month are now public.
The sole zero-day flaw this month is CVE-2025-33053 , a remote code execution flaw in the Windows implementation of WebDAV — an HTTP extension that lets users remotely manage files and directories on a server. While WebDAV isn’t enabled by default in Windows, its presence in legacy or specialized systems still makes it a relevant target, said Seth Hoyt , senior security engineer at Automox .
Adam Barnett , lead software engineer at Rapid7 , said Microsoft’s advisory for CVE-2025-33053 does
Krebs
Patch Tuesday, June 2025 Edition
blogs_krebs·2025-06-10·CVSS 8.8
CVE-2025-33053 [HIGH] Patch Tuesday, June 2025 Edition
Microsoft today released security updates to fix at least 67 vulnerabilities in its Windows operating systems and software. Redmond warns that one of the flaws is already under active attack, and that software blueprints showing how to exploit a pervasive Windows bug patched this month are now public.
The sole zero-day flaw this month is CVE-2025-33053, a remote code execution flaw in the Windows implementation of WebDAV — an HTTP extension that lets users remotely manage files and directories on a server. While WebDAV isn’t enabled by default in Windows, its presence in legacy or specialized systems still makes it a relevant target, said Seth Hoyt, senior security engineer at Automox.
Adam Barnett, lead software engineer at Rapid7, said Microsoft’s advisory for CVE-2025-33053 does not m
Checkpoint
9th June – Threat Intelligence Report
blogs_checkpoint·2025-06-09
CVE-2025-49113 9th June – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 9th June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 9th June, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
American tax company, Optima Tax Relief, has disclosed a ransomware attack that resulted in the theft of 69GB of sensitive data, including corporate records and customer case files containing personal information such as Social Security numbers, phone numbers, and home addresses. The attack impacted the company’s servers in a dou
Talos
Everyone's on the cyber target list
blogs_talos·2025-06-05
Everyone's on the cyber target list
Welcome to this week’s edition of the Threat Source newsletter.
I’ve discovered that being a rent guarantor for someone is an involved experience. While I’m glad that I can help out a loved one secure a better rental property, the process of verifying my identity and ability to cover any missed payments required handing over far more personal and financial data than I was comfortable with.
I asked the agent about their information security policies and cybersecurity posture. I was relieved to hear that they delete all the personal data within two weeks of processing, but I was concerned that the person dealing with my dossier didn’t think that they were at risk of a cyber attack. They believed that because they had a low online profile and their organisation was small, they didn’t presen
Talos
Everyone's on the cyber target list
blogs_talos·2025-06-05
Everyone's on the cyber target list
## Everyone's on the cyber target list
Welcome to this week’s edition of the Threat Source newsletter.
I’ve discovered that being a rent guarantor for someone is an involved experience. While I’m glad that I can help out a loved one secure a better rental property, the process of verifying my identity and ability to cover any missed payments required handing over far more personal and financial data than I was comfortable with.
I asked the agent about their information security policies and cybersecurity posture. I was relieved to hear that they delete all the personal data within two weeks of processing, but I was concerned that the person dealing with my dossier didn’t think that they were at risk of a cyber attack. They believed that because they had a low online profile and their or
Bleepingcomputer
Google patches new Chrome zero-day bug exploited in attacks
blogs_bleepingcomputer·2025-06-03·CVSS 8.3
[HIGH] Google patches new Chrome zero-day bug exploited in attacks
## Google patches new Chrome zero-day bug exploited in attacks
## Sergiu Gatlan
Google says the issue was mitigated one day later by a configuration change the company pushed to the Stable channel across all Chrome platforms.
On Monday, it also fixed the zero-day with the release of 137.0.7151.68/.69 for Windows/Mac and 137.0.7151.68 for Linux, versions that are rolling out to users in the Stable Desktop channel over the coming weeks.
While Chrome will automatically update when new security patches are available, users can speed up the process by going to the Chrome menu > Help > About Google Chrome, letting the update finish, and clicking the 'Relaunch' button to install it immediately.
While Google has already confirmed that CVE-2025-5419 is being exploited in the wild, the company
2025-06-03
Published
2025-06-05
Added to CISA KEV
Exploited in the wild