Article Details

Scrape Timestamp (UTC): 2025-06-03 04:27:26.460

Source: https://thehackernews.com/2025/06/new-chrome-zero-day-actively-exploited.html

Original Article Text

Click to Toggle View

New Chrome Zero-Day Actively Exploited; Google Issues Emergency Out-of-Band Patch. Google on Monday released out-of-band fixes to address three security issues in its Chrome browser, including one that it said has come under active exploitation in the wild. The high-severity flaw is being tracked as CVE-2025-5419, and has been flagged as an out-of-bounds read and write vulnerability in the V8 JavaScript and WebAssembly engine. "Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page," reads the description of the bug on the NIST's National Vulnerability Database (NVD). Google credited Clement Lecigne and Benoît Sevens of Google Threat Analysis Group (TAG) with discovering and reporting the flaw on May 27, 2025. It also noted that the issue was addressed the next day by pushing out a configuration change to the Stable version of the browser across all platforms. As is customary, the advisory is light on details regarding the nature of the attacks leveraging the vulnerability or the identity of the threat actors perpetrating them. This is done so to ensure that a majority of users are updated with a fix and to prevent other bad actors from joining the exploitation bandwagon. "Google is aware that an exploit for CVE-2025-5419 exists in the wild," the tech giant acknowledged. CVE-2025-5419 is the second actively exploited zero-day to be patched by Google this year after CVE-2025-2783 (CVSS score: 8.3), which was identified by Kaspersky as being weaponized in attacks targeting organizations in Russia. Users are recommended to upgrade to Chrome version 137.0.7151.68/.69 for Windows and macOS, and version 137.0.7151.68 for Linux to safeguard against potential threats. Users of Chromium-based browsers such as Microsoft Edge, Brave, Opera, and Vivaldi are also advised to apply the fixes as and when they become available.

Daily Brief Summary

MALWARE // Google Patches Chrome Zero-Day Exploited by Attackers

Google released emergency security updates for Chrome to fix a critical zero-day vulnerability (CVE-2025-5419) exploited in the wild.

The vulnerability involved an out-of-bounds read and write in the Chrome V8 engine, affecting all platforms.

The exploit allowed attackers to cause heap corruption through a crafted HTML page, posing significant security risks.

Detected and reported by Google's Threat Analysis Group, the flaw was patched within a day of its reporting.

This marks the second zero-day vulnerability in Chrome that Google has addressed this year, following CVE-2025-2783.

Chrome users are urged to update their browsers to the latest versions to protect against potential exploits.

Other Chromium-based browsers like Edge and Opera are also recommended to update as patches become available.