LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-5825: Google Chromium V8 Out-of-Bounds Write Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 8, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 22, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-5825 to its Known Exploited Vulnerabilities catalog on Jun 8, 2022, with a federal patch deadline of Jun 22, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect…

CVE-2019-5825 is an out-of-bounds write vulnerability in the Google Chromium V8 JavaScript engine. A remote attacker can potentially trigger heap corruption by enticing a user to open a crafted HTML page. Because V8 underpins multiple Chromium-based browsers—including Google Chrome, Microsoft Edge, and Opera—the issue can expose a wide range of desktop and managed endpoints. CISA directs organizations to apply updates per vendor instructions; known ransomware use is not documented.

How it works

The weakness is classified as CWE-787 (out-of-bounds write). In engines like V8, memory management for JavaScript objects and the heap must stay within allocated bounds. An out-of-bounds write occurs when code writes data past the end (or before the start) of a buffer. In this case, the CISA summary states that a crafted HTML page can lead to heap corruption.

An attacker typically delivers the page through ordinary web browsing or a malicious link. Successful corruption of heap metadata or object layouts can, in the general class of such flaws, allow further memory-safety bypasses. Exact exploit mechanics, reliability, and privilege outcomes are not detailed in the provided facts; defenders should treat any unpatched Chromium V8 instance as capable of remote code-execution risk via web content and confirm full technical detail against the vendor advisory.

Am I affected? How to find it in your systems

Chromium V8 runs inside browsers and embedded WebView components on workstations, VDI images, kiosks, and some cross-platform applications that ship a Chromium runtime. Inventory every browser and Electron-style app that may bundle V8.

How to remediate

Patch first. Apply the updates issued by each browser or product vendor that incorporates the fixed Chromium V8 code, following the vendor’s instructions as required by CISA. Prioritize internet-facing and high-privilege user endpoints.

If you can't patch immediately

Reduce exposure until updates can be applied.

If your data may have been exposed

Actively exploited browser engine flaws can lead to endpoint compromise and subsequent data theft. If you suspect exploitation, isolate affected hosts, preserve memory and disk evidence, rotate credentials accessible from those systems, and follow your incident-response plan. You can run a free exposure scan of your email addresses against known breach data to check whether associated accounts already appear in public dumps, then prioritize password resets and monitoring for those identities.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedGoogle · Chromium V8
WeaknessCWE-787
Added to CISA KEVJun 8, 2022
Federal patch deadlineJun 22, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities