CVE-2025-3070: Medium Insufficient validation of untrusted input in Extensions.
Chromium: CVE-2025-3070 Insufficient validation of untrusted input in Extensions
Other sources
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-3070?
CVE-2025-3070 has a medium severity rating.
How do I fix CVE-2025-3070?
To fix CVE-2025-3070, update Google Chrome to version 135.0.7049.52 or later.
What impact does CVE-2025-3070 have on users?
CVE-2025-3070 allows a remote attacker to perform privilege escalation via a crafted HTML page.
What software is affected by CVE-2025-3070?
CVE-2025-3070 affects Google Chrome versions prior to 135.0.7049.52.
Is CVE-2025-3070 exploitable remotely?
Yes, CVE-2025-3070 is exploitable remotely through a crafted HTML page.