Google has released an emergency out-of-band update to address a critical zero-day vulnerability in its Chrome browser, identified as CVE-2025-5419. This high-severity flaw, with a CVSS score of 8.8, affects the V8 JavaScript and WebAssembly engine and has been actively exploited in the wild

Vulnerability Details

CVE-2025-5419 is characterized as an out-of-bounds read and write issue within the V8 engine. Exploitation of this vulnerability could allow a remote attacker to corrupt the heap memory via a crafted HTML page, potentially leading to arbitrary code execution. Google’s Threat Analysis Group (TAG) researchers, Clement Lecigne and Benoît Sevens, discovered and reported the flaw on May 27, 2025. A fix was promptly implemented the following day through a configuration change to the Stable version of Chrome across all platforms.

As per Google’s advisory, “Google is aware that an exploit for CVE-2025-5419 exists in the wild.” However, specific details regarding the nature of the attacks or the threat actors involved have not been disclosed to prevent further exploitation

Recommended Actions

Users are strongly advised to update their Chrome browsers to the latest versions to mitigate potential risks:

  • Windows and macOS: Version 137.0.7151.68 or 137.0.7151.69
  • Linux: Version 137.0.7151.68

Additionally, users of Chromium-based browsers such as Microsoft Edge, Brave, Opera, and Vivaldi should apply the respective updates as they become available.

Context and Precedence

This marks the second actively exploited zero-day vulnerability in Chrome addressed by Google in 2025. Earlier this year, CVE-2025-2783 was patched after being weaponized in attacks targeting organizations in Russia.

The swift identification and remediation of CVE-2025-5419 underscore the importance of timely updates and vigilance in cybersecurity practices.

Please subscribe to the Newsletter so that you do not miss any critical update

Leave a Reply

Your email address will not be published. Required fields are marked *