CVE-2025-3620

Published Apr 16, 2025

Last updated 2 months ago

Overview

Description
Use after free in USB in Google Chrome prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Source
chrome-cve-admin@google.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

chrome-cve-admin@google.com
CWE-416
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-416

Social media

Hype score
Not currently trending
  1. ⚠️Múltiples vulnerabilidades de Microsoft Edge ❗CVE-2025-3619 ❗CVE-2025-3620 ➡️Más info: https://t.co/SNtDhGamBU https://t.co/oePnY8Co1t

    @CERTpy

    23 Apr 2025

    67 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. “Google Chrome” brauzerində boşluq (CVE-2025-3619 və CVE-2025-3620) aşkar olunub. #ETX #certaz #cybersecurity #kibertəhlükəsizlik #xəbərdarlıq https://t.co/YAl2fdVdOM

    @CERTAzerbaijan

    21 Apr 2025

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Threat Alert: Critical Chrome Vulnerability Exposes Users to Data Theft and Unauthorized Acces CVE-2025-3620 CVE-2025-3619 Severity: ⚠️ Critical Maturity: 🧨 Trending Learn more: https://t.co/fTKIXnSZi4 #CyberSecurity #ThreatIntel #InfoSec

    @fletch_ai

    17 Apr 2025

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2025-3620 Use after free in USB in Google Chrome prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium securi… https://t.co/vaq0CTOttc

    @CVEnew

    17 Apr 2025

    127 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Vulnérabilités dans Google Chrome: Version affectés: Chrome antérieures à  135.0.7049.95/.96  pour Windows & Mac et antérieures à 135.0.7049.95 pour Linux Identificateurs: CVE-2025-3619, CVE-2025-3620 Risque: Prise de contrôle du système affecté.

    @DLupin_

    16 Apr 2025

    24 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. 🚨 Google patches 2 critical memory bugs in Chrome 135: - CVE-2025-3619 (heap overflow in Codecs) - CVE-2025-3620 (use-after-free in USB) Update ASAP to stay safe from potential web-based attacks. https://t.co/YJZSx38Oaa #CyberSecurity #Google #chrome

    @dCypherIO

    16 Apr 2025

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Midnight Blizzard benytter ny GrapeLoader-malware i phishing-kampanje rettet mot ambassader. Kritisk Chrome-sikkerhetsoppdatering: Installer nå for å unngå CVE-2025-3619 og CVE-2025-3620. https://t.co/Inr7V1aBJc

    @TelenorSOC

    16 Apr 2025

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Critical Chrome update patches CVE-2025-3619 & CVE-2025-3620—actively exploited zero-days allowing RCE and data theft. Update immediately: https://t.co/8Ko1Ml5AdG #CyberSecurity #BrowserSecurity

    @adriananglin

    16 Apr 2025

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. A new vulnerability with increased severity was disclosed for Google Chrome (CVE-2025-3620) https://t.co/6LHEOXLNzc

    @vuldb

    16 Apr 2025

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations