PT-2025-23563 · Google +3 · Google Chrome +4

Benoît Sevens

+1

·

Published

2025-05-27

·

Updated

2025-08-26

·

CVE-2025-5419

CVSS v2.0
10
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C

**Name of the Vulnerable Software and Affected Versions:**

Google Chrome versions prior to 137.0.7151.68

Microsoft Edge versions prior to 137.0.7151.68

Opera versions prior to 119.0.5497.70

Opera GX versions prior to 119.0.5497.68

**Description:**

A high-severity out-of-bounds read and write vulnerability exists in the V8 JavaScript and WebAssembly engine. This flaw allows a remote attacker to potentially exploit heap corruption via a crafted HTML page, potentially leading to arbitrary code execution. The vulnerability is actively exploited in the wild.

**Recommendations:**

Update Google Chrome to version 137.0.7151.68 or later.

Update Microsoft Edge to version 137.0.7151.68 or later.

Update Opera to version 119.0.5497.70 or later.

Update Opera GX to version 119.0.5497.68 or later.

Fix

RCE

Out of bounds Read

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2025-06341
CVE-2025-5419
DSA-5935-1
MGASA-2025-0187

Affected Products

Astra Linux
Debian
Google Chrome
Red Os
V8