CVE-2025-3620 is a high-severity use-after-free vulnerability in Google Chrome, specifically affecting the USB component prior to version 135.0.7049.95. This flaw allows a remote attacker to trigger heap corruption and potentially execute arbitrary code by enticing a user to visit a specially crafted HTML page. The vulnerability carries a CVSS score of 8.8 (High), indicating a network-based attack with low complexity, requiring user interaction, and leading to high impacts on confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and community discussion and media coverage are minimal, suggesting limited current exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 135.0.7049.95CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 135.0.7049.95, < 135.0.7049.95CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.