CVE-2019-5825

MEDIUM(6.5)KEVLikely Exploited

Google Chromium V8 Out-of-Bounds Write Vulnerability

Description

CVE-2019-5825 is an out-of-bounds write vulnerability in the Google Chromium V8 JavaScript engine that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. The vulnerability affects multiple web browsers that utilize the Chromium engine, including Google Chrome, Microsoft Edge, and Opera. Successful exploitation can lead to arbitrary code execution within the browser sandbox, potentially enabling further system compromise through sandbox escape chains. CISA has added CVE-2019-5825 to its Known Exploited Vulnerabilities catalog, and with an EPSS score of 78.5% (99th percentile), this Chromium V8 vulnerability poses a critical threat to users running unpatched browsers.

KEV Information

Vendor
Google
Product
Chromium V8
Date Added
June 8, 2022
Due Date
June 22, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
3.6

CWEs

Affected Products

VendorProductVersion
googlechrome< 73.0.3683.86

Multiple CVSS Assessments

Source: [email protected](Primary)
6.5
MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
6.5
MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

References

Weakness Type

CWE-787: Out-of-bounds Write

CVE-2019-5825 exploits an out-of-bounds write vulnerability in the Chromium V8 engine, where the JavaScript engine writes data beyond the intended buffer boundaries during execution of crafted JavaScript code. This out-of-bounds write corrupts adjacent heap memory, which attackers can leverage to gain control of program execution flow and achieve arbitrary code execution within the browser process.

Learn more: CWE-787 — Out-of-bounds Write

Impact Analysis

CVE-2019-5825 is a high-severity vulnerability in the Chromium V8 JavaScript engine that is remotely exploitable simply by visiting a malicious web page. No authentication or special privileges are required — any user browsing to an attacker-controlled page can be exploited. The attack complexity is relatively low as the exploit is delivered through standard web content. Confidentiality and integrity are critically impacted as successful heap corruption exploitation can lead to arbitrary code execution, allowing the attacker to read sensitive browser data, steal credentials, or install malware. While the initial code execution occurs within the browser sandbox, sophisticated attackers may chain this with sandbox escape vulnerabilities for full system compromise. The EPSS score of 78.5% (99th percentile) indicates extremely high exploitation probability, and the broad attack surface — affecting all Chromium-based browsers — amplifies the risk significantly.

Exploit Maturity

CISA has confirmed active exploitation of CVE-2019-5825 by including it in the Known Exploited Vulnerabilities catalog, with a remediation deadline of June 22, 2022. The EPSS score of 78.5% (99th percentile) reflects very high exploitation probability. No specific ransomware campaigns have been publicly attributed to this vulnerability, but V8 out-of-bounds write vulnerabilities are frequently used in browser-based exploit chains by both state-sponsored actors and cybercriminal groups for drive-by download attacks, watering hole campaigns, and targeted exploitation.

Remediation

  1. Update all Chromium-based browsers immediately to versions that patch CVE-2019-5825, including Google Chrome, Microsoft Edge, Opera, and any other browsers built on the Chromium engine.
  2. Enable automatic browser updates across all managed endpoints to ensure that future V8 security patches are applied without delay.
  3. Deploy browser isolation technology for high-risk browsing scenarios, which renders web content in an isolated environment and prevents V8 exploits from reaching the local system.
  4. Implement Content Security Policy (CSP) headers on organizational web applications to reduce the risk of malicious JavaScript execution, and consider deploying web filtering to block known exploit delivery domains.
  5. Monitor endpoint detection systems for indicators of browser-based exploitation, including unusual child process creation from browser processes, unexpected memory allocation patterns, or browser crashes that may indicate exploitation attempts.

Technical Details

CVE-2019-5825 is an out-of-bounds write vulnerability in the V8 JavaScript engine used by Chromium-based browsers. The vulnerability occurs when V8 processes specially crafted JavaScript that causes the engine to write data beyond the allocated boundaries of a heap buffer. This out-of-bounds write corrupts adjacent heap metadata or object data, which an attacker can carefully manipulate through heap grooming techniques to overwrite critical data structures such as object vtables, function pointers, or array length fields. By controlling what data overwrites these structures, the attacker achieves a reliable write primitive that can be escalated to arbitrary code execution within the renderer process. The crafted HTML page triggers the vulnerable code path in V8's JIT compiler or runtime, making the exploit deliverable through any web content rendering context.

Frequently Asked Questions

Is CVE-2019-5825 being actively exploited?

Yes. CISA has added CVE-2019-5825 to its Known Exploited Vulnerabilities catalog, confirming active exploitation. The EPSS score of 78.5% (99th percentile) indicates very high exploitation probability. No ransomware association has been confirmed, but V8 vulnerabilities are high-value targets for sophisticated attack groups.

What products are affected by CVE-2019-5825?

CVE-2019-5825 affects all web browsers utilizing the Chromium V8 JavaScript engine, including Google Chrome, Microsoft Edge, Opera, Brave, and Vivaldi. Any unpatched Chromium-based browser is vulnerable when visiting a malicious web page.

How do I fix CVE-2019-5825?

Update all Chromium-based browsers to the latest patched versions. Enable automatic browser updates on all managed devices. For additional protection, deploy browser isolation technology and web filtering to reduce exposure to malicious web content.

How severe is CVE-2019-5825?

CVE-2019-5825 is a high-severity out-of-bounds write vulnerability with an EPSS score of 78.5% in the 99th percentile. It enables remote code execution through a crafted web page, requiring no user interaction beyond visiting the page. The broad impact across all Chromium-based browsers makes this a widespread threat.

CVSS Score

6.5
MEDIUM(6.5)

EPSS Score

EPSS Score55.93%
EPSS Percentile99.0%

Dates

PublishedNovember 25, 2019
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.