PT-2025-9736 · Google+3 · Google Chrome+3

Topi Lassila

·

Publicado

2025-03-04

·

Atualizado

2025-04-03

·

CVE-2025-1915

CVSS v2.0

9.4

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 134.0.6998.35
Description The issue is related to improper limitation of a pathname to a restricted directory in DevTools. An attacker could bypass file access restrictions by convincing a user to install a malicious extension, which could then utilize a crafted Chrome Extension to exploit this issue.
Recommendations For versions prior to 134.0.6998.35, update to version 134.0.6998.35 or later to resolve the issue.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2025-4164
ALT-PU-2025-4366
BDU:2025-02670
CVE-2025-1915
DSA-5875-1
MGASA-2025-0091
OPENSUSE-SU-2025:0084-1
OPENSUSE-SU-2025:14854-1

Produtos afetados

Alt Linux
Debian
Google Chrome
Red Os