CVE-2025-34090: Google Chrome AppBound Cookie Encryption Bypass via COM Hijacking
Published Jul 2, 2025
·Updated
Rejected reason: Neither filed by Chrome nor a valid security vulnerability.
Affected Software
2 affected components
Google Chrome
Chromium Chromium-based browsers
Event History
Jul 2, 2025
CVE Published
via MITRE·07:25 PM
Rejected
via MITRE·07:25 PM
Data Sourced
via NVD·08:15 PM
Description
Jul 24, 2025
Rejected
via MITRE·01:25 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-34090?
CVE-2025-34090 is considered a low-severity vulnerability due to its requirements for local access to exploit.
2
How do I fix CVE-2025-34090?
To mitigate CVE-2025-34090, ensure that you are using an updated version of Google Chrome or Google Chromium.
3
Who is affected by CVE-2025-34090?
CVE-2025-34090 affects users of Google Chrome and Google Chromium that utilize the AppBound cookie encryption mechanism.
4
What type of attacks can be executed using CVE-2025-34090?
A local low-privileged attacker can potentially hijack COM class identifier (CLSID) registration to exploit CVE-2025-34090.
5
Is CVE-2025-34090 related to any specific functionality in Chrome?
Yes, CVE-2025-34090 is specifically related to the AppBound cookie encryption mechanism in Google Chrome.