Improper Pathname Limitation in Google Chrome DevTools for Windows
CVE-2025-1915

8.1HIGH

Key Information:

Vendor
Google
Status
Vendor
CVE Published:
5 March 2025

Summary

A security flaw exists in Google Chrome's DevTools for Windows that allows an attacker to exploit improper pathname restrictions. If a user installs a malicious extension, the attacker can bypass file access limitations to the user's system, potentially leading to unauthorized file access or disclosure of sensitive information.

Affected Version(s)

Chrome 134.0.6998.35

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.