Google on Monday released out-of-band fixes to address three security issues in its Chrome browser, including one that it said has come under active exploitation in the wild.
The high-severity flaw is being tracked as CVE-2025-5419, and has been flagged as an out-of-bounds read and write vulnerability in the V8 JavaScript and WebAssembly engine.
”Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page,” reads the description of the bug on the NIST’s National Vulnerability Database (NVD).
Google credited Clement Lecigne and Benoît Sevens of Google Threat Analysis Group (TAG) with discovering and reporting the flaw on May 27, 2025. It also noted that the issue was addressed the next day by pushing out a configuration change to the Stable version of the browser across all platforms.
Här har du Mackens Nyheter det senaste dygnet (10 januari 2026)
Här har du Mackens Nyheter det senaste dygnet (10 januari 2026) ChatGPT vs Gemini: Prisstriden på hemmaplan: vad kostar det? Kampen om de svenska användarna är intensiv och båda jättarna har lagt sina priser på en liknande nivå för att…
