PT-2025-9736 · Google+3 · Google Chrome+3

Topi Lassila

·

Published

2025-03-04

·

Updated

2025-04-03

·

CVE-2025-1915

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 134.0.6998.35
Description The issue is related to improper limitation of a pathname to a restricted directory in DevTools. An attacker could bypass file access restrictions by convincing a user to install a malicious extension, which could then utilize a crafted Chrome Extension to exploit this issue.
Recommendations For versions prior to 134.0.6998.35, update to version 134.0.6998.35 or later to resolve the issue.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

ALT-PU-2025-4164
ALT-PU-2025-4366
BDU:2025-02670
CVE-2025-1915
DSA-5875-1
MGASA-2025-0091
OPENSUSE-SU-2025:0084-1
OPENSUSE-SU-2025:14854-1

Affected Products

Alt Linux
Debian
Google Chrome
Red Os