CVE-2025-3069 is a medium-severity vulnerability affecting Google Chrome prior to version 135.0.7049.52, stemming from an inappropriate implementation in Extensions. This flaw allows a remote attacker to achieve privilege escalation through a specially crafted HTML page. With a CVSS score of 8.8 (HIGH), it presents a significant risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, including mention in a Microsoft Patch Tuesday article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 135.0.7049.52CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 135.0.7049.52, < 135.0.7049.52CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.