CVE-2025-5419
גבוהה 8.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 6% (אחוזון 100) נכון ל-26/7/2026
- CWE
- CWE-125, CWE-787
מוצרים מושפעים
google: chrome; microsoft: edge chromium
קישורים
- https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-deskto… Release Notes
- https://issues.chromium.org/issues/420636529 Permissions Required
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-5419 Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource