Another in-the-wild bug in TurboFan. We should improve how we build JavaScript JITs somewhat.
[N/A][420636529] High CVE-2025-5419: Out of bounds read and write in V8. Reported by Clement Lecigne and Benoît Sevens of Google Threat Analysis Group on 2025-05-27. This issue was mitigated on 2025-05-28 by a configuration change pushed out to Stable across all Chrome platforms […] Google is aware that an exploit for CVE-2025-5419 exists in the wild.
The patch (“Weaken alias analysis in store-store elimination”): https://chromium.googlesource.com/v8/v8.git/+/7bc0a67ebfbf44e7adab47fc2bbbe308660e27f4%5E%21/#F0