HomeSecurityPoC Exploit released for Chrome zero-day vulnerability

PoC Exploit released for Chrome zero-day vulnerability

New Chrome zero-day: Google has disclosed a critical zero-day vulnerability in the V8 JavaScript engine used by the Chrome browser . What's worrying is that, before it could release an update for all users, a proof-of-concept (PoC) exploit for the vulnerability was published and active exploitation was observed in targeted campaigns .

PoC Exploit for Chrome zero-day

Security teams and administrators are urged to immediately upgrade to Chrome version 137.0.7151.68 or later to protect themselves from potential attacks.

Chrome zero-day CVE-2025-5419

CVE -2025-5419 is an out-of-bounds (read and write) vulnerability in V8 array handling routines. An attacker can craft a malicious HTML page that embeds specially crafted JavaScript arrays, which in turn cause heap corruption when parsed by the engine. The heap corruption allows arbitrary read and write operations within the renderer process, opening the way for remote code execution under the context of the logged-in user.

See also: CISA: New Vulnerabilities in the KEV Catalog for Citrix and Git

Exploit chains typically start with the OOB primitive to leak addresses of critical V8 objects and then escalate to arbitrary writes to replace function pointers.

After exploitation, the attacker can install a second-stage payload or deliver ransomware, keyloggers, or other malware.

PoC Exploit for Chrome zero-day bug

A PoC script has been published by security researcher mistymntncop on GitHub. The main snippet, which demonstrates the OOB write, corrupts the backing store of an arr, allowing controlled replacements of adjacent memory. The PoC then leverages these primitives to compromise the V8 function dispatch table, achieving code execution in the renderer.

PoC Exploit released for Chrome zero-day vulnerability

Active exploitation has been reported, with targeted spear-phishing campaigns luring victims to compromised sites. Organizations should ensure that all endpoints are running version 137.0.7151.68 or later, block known exploit domains , and monitor for unusual V8 process behavior. They should also look for JavaScript exceptions.

See also: vtenext CRM: Multiple vulnerabilities allow RCE attacks

Google's official update addresses the root of the problem by fixing the bounds check logic in V8's array implementation. With the rapid publication of the PoC code and confirmed attacks, defenders need to act quickly to eliminate this threat.

Vulnerabilities in the Chrome browser

The emergence of a new Chrome zero-day in the V8 engine is a reminder of the ongoing battle between attackers and software vendors for control of the browser attack surface. Zero-days affecting JavaScript engines are considered among the most dangerous because they exploit the fact that browsers are the “gateway” to the internet and are used by billions of users in real time. Publishing a PoC before general release of updates dramatically increases the risk, as it reduces the reaction time and facilitates rapid adoption of the exploit by a wider range of threat groups.

Experience shows that such vulnerabilities are often part of complex exploit chains, where the initial breach in V8 is exploited in combination with sandbox escapes or privilege escalations to gain full control of the system. This means that the threat is not limited to the browser context, but can extend to critical business applications and infrastructure. For organizations that rely on web-based tools, the risk of lateral movement via browsers is particularly high.

See also: Tableau Server: Critical vulnerability allows system compromise

PoC Exploit released for Chrome zero-day vulnerability

The disclosure of active spear-phishing campaigns demonstrates that attackers are not limited to theoretical exploitation of the vulnerability, but have already adapted their strategy to target specific user profiles. This reinforces the need not only for immediate notification, but also for implementing additional measures such as network filtering of known exploit domains, user education against phishing techniques, and active monitoring for anomalies in JavaScript engine behavior.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Ultimately, the incident highlights the importance of proactive security: continuous code review, collaboration with researchers, and accelerated patch release cycles. Zero-days are inevitable; the difference comes from how quickly and effectively defenders can respond.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS