Privilege Escalation Vulnerability in Google Chrome for Android
CVE-2025-3067

8.8HIGH

Key Information:

Vendor
Google
Status
Vendor
CVE Published:
2 April 2025

Summary

A vulnerability in the Custom Tabs feature of Google Chrome on Android devices can be exploited by an attacker to achieve privilege escalation. This occurs when users are misled into performing specific UI gestures, allowing for the execution of a malicious app. Users are advised to update their browser to the latest version to mitigate this risk.

Affected Version(s)

Chrome 135.0.7049.52

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.