PT-2025-16900 · Google+5 · Google Chrome+5

Retsew0X01

·

Published

2025-01-01

·

Updated

2025-07-30

·

CVE-2025-3620

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 135.0.7049.95
Description A use after free issue in the USB component of Google Chrome allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This issue is related to the UsbChooserController holding a raw pointer to the requesting RenderFrameHost, which is destroyed before the chooser controller, resulting in a use after free condition. The estimated severity of this issue is high.
Recommendations For Google Chrome versions prior to 135.0.7049.95, update to version 135.0.7049.95 or later to resolve the issue. As a temporary workaround, consider restricting access to USB-related features in Google Chrome until the update is applied.

Fix

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2025-6248
BDU:2025-04921
CVE-2025-3620
DSA-5903-1
MGASA-2025-0140
OPENSUSE-SU-2025:0133-1
OPENSUSE-SU-2025:15027-1

Affected Products

Alt Linux
Astra Linux
Chromium
Debian
Google Chrome
Red Os