Padding Oracle Vulnerability in Google Chrome's AppBound Encryption Mechanism
CVE-2025-34091

8.8HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
2 July 2025

What is CVE-2025-34091?

A vulnerability in Google Chrome’s AppBound cookie encryption allows local attackers to exploit observable decryption failure behavior. By sending malformed ciphertexts to the Chrome elevation service, attackers can determine padding and MAC errors, leading to a padding oracle attack. This vulnerability compromises the integrity of the AppBound Encryption, facilitating low-privileged cookie theft. The issue stems from interactions between Chrome’s implementation and Windows DPAPI's logging of decryption errors, enabling the recovery of sensitive cookie keys. Other Chromium-based browsers may also be at risk if they utilize similar encryption mechanisms.

Affected Version(s)

Chrome Windows 127 < 129

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ari Novick of CyberArk Labs
.
CVE-2025-34091 : Padding Oracle Vulnerability in Google Chrome's AppBound Encryption Mechanism