Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop.html | release notes |
https://issues.chromium.org/issues/420636529 | permissions required |
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-5419 | third party advisory |