CVE-2025-5419: Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2025-06-05. EPSS: 7.8% chance of exploitation in the next 30 days.
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Affected products
- Google Chrome: before 137.0.7151.68 (fixed in 137.0.7151.68)
- Microsoft Edge Chromium: before 137.0.3296.62 (fixed in 137.0.3296.62)
Published 2025-06-03. Last modified 2026-06-17.