CVE-2025-5419: Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
Chromium: CVE-2025-5419 Out of bounds read and write in V8
Other sources
Google Chromium V8 contains an out-of-bounds read and write vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
— CISA
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
— NVD
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. Google is aware that an exploit for CVE-2025-5419 exists in the wild.
— Microsoft
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-5419?
CVE-2025-5419 has a severity rating of High in terms of vulnerability severity.
How do I fix CVE-2025-5419?
To fix CVE-2025-5419, update Google Chrome to version 137.0.7151.68 or later.
What does CVE-2025-5419 affect?
CVE-2025-5419 affects Google Chrome versions prior to 137.0.7151.68.
What kind of vulnerability is CVE-2025-5419?
CVE-2025-5419 is an out of bounds read and write vulnerability found in V8 in Google Chrome.
Can CVE-2025-5419 be exploited remotely?
Yes, CVE-2025-5419 allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.