CVE-2025-3067: Inappropriate implementation in Custom Tabs
Chromium: CVE-2025-3067 Inappropriate implementation in Custom Tabs
Other sources
Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform privilege escalation via a crafted app. (Chromium security severity: Medium)
— NVD
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-3067?
The severity of CVE-2025-3067 is classified as Medium.
How do I fix CVE-2025-3067?
To fix CVE-2025-3067, update Google Chrome on Android to version 135.0.7049.52 or later.
What type of vulnerability is CVE-2025-3067?
CVE-2025-3067 is a privilege escalation vulnerability due to inappropriate implementation in Custom Tabs in Google Chrome on Android.
Who is affected by CVE-2025-3067?
CVE-2025-3067 affects users of Google Chrome on Android versions prior to 135.0.7049.52.
What could an attacker achieve with CVE-2025-3067?
An attacker exploiting CVE-2025-3067 could perform privilege escalation by convincing a user to engage in specific UI gestures.