New Chrome zero-day: Google has disclosed a critical zero-day vulnerability in the V8 JavaScript engine used by the Chrome browser . What's worrying is that, before it could release an update for all users, a proof-of-concept (PoC) exploit for the vulnerability was published and active exploitation was observed in targeted campaigns .

Security teams and administrators are urged to immediately upgrade to Chrome version 137.0.7151.68 or later to protect themselves from potential attacks.
Chrome zero-day CVE-2025-5419
CVE -2025-5419 is an out-of-bounds (read and write) vulnerability in V8 array handling routines. An attacker can craft a malicious HTML page that embeds specially crafted JavaScript arrays, which in turn cause heap corruption when parsed by the engine. The heap corruption allows arbitrary read and write operations within the renderer process, opening the way for remote code execution under the context of the logged-in user.
See also: CISA: New Vulnerabilities in the KEV Catalog for Citrix and Git
Exploit chains typically start with the OOB primitive to leak addresses of critical V8 objects and then escalate to arbitrary writes to replace function pointers.
After exploitation, the attacker can install a second-stage payload or deliver ransomware, keyloggers, or other malware.
PoC Exploit for Chrome zero-day bug
A PoC script has been published by security researcher mistymntncop on GitHub. The main snippet, which demonstrates the OOB write, corrupts the backing store of an arr, allowing controlled replacements of adjacent memory. The PoC then leverages these primitives to compromise the V8 function dispatch table, achieving code execution in the renderer.

Active exploitation has been reported, with targeted spear-phishing campaigns luring victims to compromised sites. Organizations should ensure that all endpoints are running version 137.0.7151.68 or later, block known exploit domains , and monitor for unusual V8 process behavior. They should also look for JavaScript exceptions.
See also: vtenext CRM: Multiple vulnerabilities allow RCE attacks
Google's official update addresses the root of the problem by fixing the bounds check logic in V8's array implementation. With the rapid publication of the PoC code and confirmed attacks, defenders need to act quickly to eliminate this threat.
Vulnerabilities in the Chrome browser
The emergence of a new Chrome zero-day in the V8 engine is a reminder of the ongoing battle between attackers and software vendors for control of the browser attack surface. Zero-days affecting JavaScript engines are considered among the most dangerous because they exploit the fact that browsers are the “gateway” to the internet and are used by billions of users in real time. Publishing a PoC before general release of updates dramatically increases the risk, as it reduces the reaction time and facilitates rapid adoption of the exploit by a wider range of threat groups.
Experience shows that such vulnerabilities are often part of complex exploit chains, where the initial breach in V8 is exploited in combination with sandbox escapes or privilege escalations to gain full control of the system. This means that the threat is not limited to the browser context, but can extend to critical business applications and infrastructure. For organizations that rely on web-based tools, the risk of lateral movement via browsers is particularly high.
See also: Tableau Server: Critical vulnerability allows system compromise

The disclosure of active spear-phishing campaigns demonstrates that attackers are not limited to theoretical exploitation of the vulnerability, but have already adapted their strategy to target specific user profiles. This reinforces the need not only for immediate notification, but also for implementing additional measures such as network filtering of known exploit domains, user education against phishing techniques, and active monitoring for anomalies in JavaScript engine behavior.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Ultimately, the incident highlights the importance of proactive security: continuous code review, collaboration with researchers, and accelerated patch release cycles. Zero-days are inevitable; the difference comes from how quickly and effectively defenders can respond.
