Improper Pathname Limitation in Google Chrome DevTools for Windows
CVE-2025-1915
8.1HIGH
Summary
A security flaw exists in Google Chrome's DevTools for Windows that allows an attacker to exploit improper pathname restrictions. If a user installs a malicious extension, the attacker can bypass file access limitations to the user's system, potentially leading to unauthorized file access or disclosure of sensitive information.
Affected Version(s)
Chrome 134.0.6998.35
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved