CVE-2025-3620: High Use after free in USB
Chromium: CVE-2025-3620 Use after free in USB
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in USB in Google Chrome prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
— MITRE
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-3620?
CVE-2025-3620 is considered a high severity vulnerability that allows use after free attacks.
How do I fix CVE-2025-3620?
To fix CVE-2025-3620, update Google Chrome to at least version 135.0.7049.95 or update Microsoft Edge (Chromium-based) to the latest version.
Which software is affected by CVE-2025-3620?
CVE-2025-3620 affects Google Chrome versions prior to 135.0.7049.95 and Microsoft Edge (Chromium-based) prior to the latest updates.
What type of vulnerability is CVE-2025-3620?
CVE-2025-3620 is classified as a use after free vulnerability that can lead to memory corruption.
Who is responsible for addressing CVE-2025-3620?
CVE-2025-3620 is addressed by both Google for Chrome and Microsoft for their Edge (Chromium-based) browser.