PT-2025-16900 · Google+5 · Google Chrome+5
Retsew0X01
·
Published
2025-01-01
·
Updated
2025-07-30
·
CVE-2025-3620
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 135.0.7049.95
Description
A use after free issue in the USB component of Google Chrome allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This issue is related to the
UsbChooserController holding a raw pointer to the requesting RenderFrameHost, which is destroyed before the chooser controller, resulting in a use after free condition. The estimated severity of this issue is high.Recommendations
For Google Chrome versions prior to 135.0.7049.95, update to version 135.0.7049.95 or later to resolve the issue. As a temporary workaround, consider restricting access to USB-related features in Google Chrome until the update is applied.
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Chromium
Debian
Google Chrome
Red Os