CVE-2025-5419 is a high-severity out-of-bounds read and write vulnerability in the V8 JavaScript engine, affecting Google Chrome and Microsoft Edge (Chromium-based) prior to version 137.0.7151.68. This flaw allows a remote attacker to achieve heap corruption by tricking a user into visiting a specially crafted HTML page. With a CVSS score of 8.8, it presents a significant risk due to its network-based attack vector, low attack complexity, and potential for high impact on confidentiality, integrity, and availability. Notably, this vulnerability is actively exploited in the wild, as confirmed by its presence in the KEV catalog and extensive media coverage, though public exploit code (Metasploit, Nuclei, ExploitDB) is not yet available. The high level of community discussion further underscores its critical nature.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 137.0.7151.68CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 137.0.3296.62CPE matchmatch criteria | cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:* | ||
>= 137.0.7151.68, < 137.0.7151.68CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.