CVE-2025-5419Exploit(google / chrome)

MEDIUMCVSS 8.8 · HIGHCISA KEV

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for google chrome systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-06-26. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-125CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • edge_chromium

Threat summary

  • Public PoC and exploit tooling are both present
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-01-29); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
chromeedge_chromium

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-01-29: 1Mentions · 2026-10-08: 1PoC Mentioned / Linked · 2026-01-29: 1Exploit Tool / Code · 2026-01-29: 1Technical Details · 2026-01-29: 101-2910-08
Signal classification1 categories
Exploit
1100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Jack Ren@bjrjk
    Exploit

    Analysis Slides and Stablized Exploit for CVE-2025-5419, a V8 Uninitialized Read Vulnerability! Shoutout to @_clem1, @benoitsevens for finding the bug and @mistymntncop for providing a wonderfully crafted exploit. https://github.com/bjrjk/CVE-2025-5419

    Post summary

    The post announces a stabilized exploit for CVE-2025-5419, links to functional exploit code, and confirms technical details about an uninitialized read in V8, but makes no claims of active exploitation or patch availability.

    2410148839.4K
    663 followersView on X
  • 【쏘가리】맞팔 지연 중 ㅠㅠ@ssogari_dev

    이게 기본 옵션인 이유가 JIT Compiler의 허점을 노려서 브라우저 해킹을 하는 경우가 많아서 그러지 않을까 생각함. 실제로 이걸 악용한 type confusion 공격이 최근에 있기도 했고 (CVE-2026-85046), 보안검사 로직을 삭제하는 bounds-check elimination도 비교적 최근이었던걸로 (CVE-2025-5419)

    1001081
    2.9K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgooglechrome---
Appmicrosoftedge_chromium---

Explore more