Posting Date: 2025/06/19
【Vulnerability Alert】Chromium-based Browsers Have Security Vulnerabilities (CVE-2025-5419), Please Confirm and Patch as Soon as Possible
- Subject: 【Vulnerability Alert】Chromium-based Browsers Have Security Vulnerabilities (CVE-2025-5419), Please Confirm and Patch as Soon as Possible
- Content:
- Forwarded from National Information Security Information Sharing and Analysis Center NISAC-200-202506-00000061
- Researchers have discovered a Heap Overflow vulnerability (CVE-2025-5419) in Chromium-based browsers such as Google Chrome, Microsoft Edge, Vivaldi, Brave, and Opera. A remote attacker can corrupt memory through a malicious HTML page, leading to remote arbitrary code execution or sandbox escape. This vulnerability has been exploited by hackers, please confirm and patch as soon as possible.
- Affected Platforms:
- Google Chrome versions prior to 137.0.7151.68 (exclusive)
- Microsoft Edge (Based on Chromium) versions prior to 137.0.3296.62 (exclusive)
- Vivaldi versions prior to 7.4.3684.50 (exclusive)
- Brave versions prior to 1.79.119 (exclusive)
- Opera versions prior to 119.0.5497.70 (exclusive)
- Suggested Measures:
- Please update Google Chrome browser to version 137.0.7151.68 (inclusive) or later
- Please update Microsoft Edge browser to version 137.0.3296.62 (inclusive) or later
- Please update Vivaldi browser to version 7.4.3684.50 (inclusive) or later
- Please update Brave browser to version 1.79.119 (inclusive) or later
- Please update Opera browser to version 119.0.5497.70 (inclusive) or later
- References:
Computer and Communications Center
Network Systems Division