CVE-2025-3067 is a privilege escalation vulnerability in Google Chrome on Android, specifically within its Custom Tabs feature, affecting versions prior to 135.0.7049.52. An attacker could exploit this by convincing a user to perform specific UI gestures within a crafted app. This vulnerability carries a high CVSS score of 8.8, indicating a significant risk with high impact on confidentiality, integrity, and availability, though it requires user interaction. Currently, there is no evidence of active exploitation, and no public exploit code or Metasploit/Nuclei modules are available, despite some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 135.0.7049.52CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 135.0.7049.52, < 135.0.7049.52CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.