CVE-2025-1915: Improper Limitation of a Pathname to a Restricted Directory in DevTools
Published Jan 20, 2025
·Updated
Chromium: CVE-2025-1915 Improper Limitation of a Pathname to a Restricted Directory in DevTools
Credit
Topi Lassila
Affected Software
5 affected componentsFixes available
Microsoft Edge<134.0.3124.51
Google Chrome<134.0.6998.35
134.0.6998.35
Microsoft Edge (Chromium-based)
All of the following
Google Chrome<134.0.6998.35
Microsoft Windows
Event History
Jan 20, 2025
CVE Published
12:00 AM
Data Sourced
12:00 AM
SeverityWeaknessAffected Software
Mar 5, 2025
CVE Published
via MITRE·03:48 AM
Data Sourced
via MITRE·03:48 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-1915?
CVE-2025-1915 has been classified as a high severity vulnerability due to its potential to bypass file access restrictions.
2
How do I fix CVE-2025-1915?
To fix CVE-2025-1915, update Google Chrome to version 134.0.6998.35 or later.
3
What systems are affected by CVE-2025-1915?
CVE-2025-1915 affects Google Chrome on Windows versions prior to 134.0.6998.35.
4
What type of attack can exploit CVE-2025-1915?
CVE-2025-1915 can be exploited by attackers who convince users to install malicious extensions that bypass file access restrictions.
5
Who is the vendor responsible for CVE-2025-1915?
The vendor responsible for CVE-2025-1915 is Google, specifically for its Chrome browser.