#VU105310 External Control of File Name or Path in Google Chromium - CVE-2025-1915


Vulnerability identifier: #VU105310

Vulnerability risk: Low

CVSSv4.0: 0.5 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-1915

CWE-ID: CWE-73

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
Google Chromium
Client/Desktop applications / Web browsers

Vendor: Google

Description

The vulnerability allows a remote attacker to overwrite files on the system.

The vulnerability exists due to improper limitations of a pathname to a restricted directory in DevTools. A remote attacker can trick the victim into performing certain actions on the website and overwrite arbitrary files on the system.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Google Chromium: 134.0.6998.0 - 134.0.6998.34


External links
https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop.html
https://crbug.com/391114799


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability