Google revealed Monday that it had quietly deployed a configuration change last week to block active exploitation of a Chrome zero-day. Google Threat Analysis Group (TAG) team members Clement Lecigne and Benoît Sevens spotted the high-severity bug, tracked as CVE-2025-5419, on May 27. It's an out-of-bounds read and write vulnerability in Chrome's V8 JavaScript engine that could allow a remote attacker to corrupt memory and potentially hijack execution via a booby-trapped HTML page. Attackers could use the exploit to expose sensitive data and/or execute arbitrary code and crash the user's machine "Google is aware that an exploit for CVE-2025-5419 exists in the wild," the advisory said, adding that "the issue was mitigated" the day after Lecigne and Sevens found the bug "by a configuration change pushed out to Stable across all Chrome platforms." While we don't have any details about who is exploiting the security hole and for what purpose, the TAG team closely tracks spyware and nation-state gangs abusing zero days for espionage purposes. As per usual, the Chocolate Factory keeps a tight lid on bug details until most of its users have updated their software with a fix. That patch landed on Monday with the release of Chrome 137.0.7151.68 and .69 for Windows and macOS, and 137.0.7151.68 for Linux, rolling out over the coming days and weeks. The Monday Chrome update also patches a medium-severity, use-after-free flaw (CVE-2025-5068) in the open-source rendering engine Blink. It's...
Google quietly pushes emergency fix for Chrome 0-day as exploit runs wild
The Register
·Jessica Lyons
·Published Jun 3, 2025
·Updated
Affected Software
3 affected components
Google Chrome=137.0.7151.68
Google Chrome=137.0.7151.69
Google Chrome
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses Google pushing an emergency fix for a Chrome zero-day vulnerability that was being actively exploited.
2
What specific vulnerability is addressed in this article?
The vulnerability is tracked as CVE-2025-5419 and is categorized as a high-severity zero-day bug.
3
What action did Google take in response to the zero-day exploit?
Google implemented a configuration change to block the exploitation of the zero-day vulnerability in Chrome.
4
Who identified the zero-day vulnerability in Google Chrome?
The vulnerability was identified by Google's Threat Analysis Group (TAG) members Clement Lecigne and Benoît Sevens.
5
On what date was the zero-day vulnerability discovered?
The zero-day vulnerability was discovered on May 27, 2025.