CVE-2025-1923: Inappropriate Implementation in Permission Prompts.
Published Dec 6, 2024
·Updated
Chromium: CVE-2025-1923 Inappropriate Implementation in Permission Prompts
Credit
Khalil Zhani
Affected Software
4 affected componentsFixes available
Microsoft Edge<134.0.3124.51
Microsoft Edge (Chromium-based)
Google Chrome<134.0.6998.35
Google Chrome<134.0.6998.35
134.0.6998.35
Event History
Dec 6, 2024
CVE Published
12:00 AM
Data Sourced
12:00 AM
SeverityWeaknessAffected Software
Mar 5, 2025
CVE Published
via MITRE·03:48 AM
Data Sourced
via MITRE·03:48 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-1923?
The severity of CVE-2025-1923 is classified as Low.
2
How do I fix CVE-2025-1923?
To fix CVE-2025-1923, update Google Chrome to version 134.0.6998.35 or later.
3
What does CVE-2025-1923 affect?
CVE-2025-1923 affects Google Chrome versions prior to 134.0.6998.35.
4
What type of attack is associated with CVE-2025-1923?
CVE-2025-1923 is associated with UI spoofing via a crafted Chrome Extension.
5
Who can exploit CVE-2025-1923?
An attacker can exploit CVE-2025-1923 by convincing a user to install a malicious extension.