PT-2025-23563 · Google+4 · V8+5

Benoît Sevens

+1

·

Published

2025-05-27

·

Updated

2026-02-17

·

CVE-2025-5419

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 137.0.7151.68 Microsoft Edge versions prior to 137.0.7151.68 Opera versions prior to 119.0.5497.70 Opera GX versions prior to 119.0.5497.68 Chromium versions prior to 137.0.7151.68
Description Google Chrome, Microsoft Edge, Opera, and Opera GX are affected by a high-severity zero-day vulnerability (CVE-2025-5419) in the V8 JavaScript engine. This vulnerability is an out-of-bounds read and write flaw that allows a remote attacker to potentially execute arbitrary code, leading to heap corruption via a crafted HTML page. The vulnerability is actively exploited in the wild. Attackers can exploit this flaw by luring victims to malicious websites. The vulnerability affects the V8 JavaScript and WebAssembly engine.
Recommendations Google Chrome versions prior to 137.0.7151.68: Update to version 137.0.7151.68 or later. Microsoft Edge versions prior to 137.0.7151.68: Update to version 137.0.7151.68 or later. Opera versions prior to 119.0.5497.70: Update to version 119.0.5497.70 or later. Opera GX versions prior to 119.0.5497.68: Update to version 119.0.5497.68 or later. Chromium versions prior to 137.0.7151.68: Update to version 137.0.7151.68 or later.

Exploit

Fix

RCE

Out of bounds Read

Memory Corruption

Weakness Enumeration

Related Identifiers

ALT-PU-2025-8435
BDU:2025-06341
CVE-2025-5419
DSA-5935-1
MGASA-2025-0187
OPENSUSE-SU-2025:15210-1
OPENSUSE-SU-2025:15249-1

Affected Products

Alt Linux
Astra Linux
Debian
Google Chrome
Red Os
V8