CVE-2019-5825: Google Chromium V8 Out-of-Bounds Write Vulnerability
Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Other sources
Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 90.0.4430.212-1~deb10u1Fixed in 116.0.5845.180-1~deb11u1Fixed in 120.0.6099.129-1~deb11u1Fixed in 119.0.6045.199-1~deb12u1Fixed in 120.0.6099.129-1~deb12u1Fixed in 120.0.6099.129-1 - Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 74.0.3729.131 - Upgrade
Upgrade
Google Chromiumto a version that resolves this vulnerability.Fixed in 73.0.3683.86 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 90.0.4430.212-1~deb10u1 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 116.0.5845.180-1~deb11u1 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 120.0.6099.129-1~deb11u1 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 119.0.6045.199-1~deb12u1 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 120.0.6099.129-1~deb12u1 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 120.0.6099.129-1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-5825?
CVE-2019-5825 is a vulnerability in the Google Chromium V8 Engine that allows a remote attacker to exploit heap corruption through a crafted HTML page.
How does CVE-2019-5825 affect Google Chrome?
CVE-2019-5825 affects Google Chrome versions prior to 73.0.3683.86.
What is the severity level of CVE-2019-5825?
CVE-2019-5825 has a severity level of 6.5, which is considered medium.
How can I fix CVE-2019-5825?
To fix CVE-2019-5825, update your Google Chrome to version 73.0.3683.86 or later.
Where can I find more information about CVE-2019-5825?
You can find more information about CVE-2019-5825 on the following references: [1](http://packetstormsecurity.com/files/156641/Google-Chrome-72-73-Array.map-Corruption.html), [2](https://chromereleases.googleblog.com/2019/04/stable-channel-update-for-desktop_30.html), [3](https://crbug.com/941743)