Cookie Encryption Bypass in Google Chrome Affecting AppBound Mechanism
CVE-2025-34092
What is CVE-2025-34092?
A cookie encryption bypass vulnerability exists within Google Chrome's AppBound mechanism, stemming from inadequate path validation logic in the elevation service. When a cookie key is encrypted, Chrome stores its executable path as metadata for validation. During decryption, this path is checked against the incoming process's path. An attacker can exploit inconsistencies in path canonicalization by creating a malicious executable named 'chrome.exe' in a similar directory, potentially allowing unauthorized access to encrypted cookies intended specifically for the Chrome process. Other Chromium-based browsers may also be susceptible if they employ similar encryption methods.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Chrome 127 < 129
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved