Junglewise Threat Intelligence

CVE-2019-5825: Google Chromium V8 Out-of-Bounds Write Vulnerability

CVE-2019-5825 · Severity: critical · CVSS 6.5 · Exploited in the wild · Published 2022-06-08

Technologies: Google Chrome, Google Chromium V8, Microsoft Edge, Opera Software Opera. Vendors: Google, Microsoft, Opera Software.

Executive brief

Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability affects multiple web browsers utilizing Chromium, including Google Chrome, Microsoft Edge, and Opera.

Affected products

  • Google Chrome < 73.0.3683.86
  • Microsoft Edge
  • Opera Software Opera

Timeline

  • 2019-04-30: patched: Stable channel update for desktop released.
  • 2019-11-25: disclosed: NVD Published Date.
  • 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats