CVE-2025-5419: Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a...

Description

Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Known Exploited

🚨 Marked as known exploited on June 3rd, 2025 (3 days ago).

Classification

CVE ID: CVE-2025-5419

Problem Types

Out of bounds read and write

Affected Products

Vendor: Google

Product: Chrome

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.12% (probability of being exploited)

EPSS Percentile: 32.81% (scored less or equal to compared to others)

EPSS Date: 2025-06-05 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-5419
https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop.html
https://issues.chromium.org/issues/420636529

Timeline