CVE-2025-1918Out-of-bounds Read in Google Chrome

Severity
8.8HIGHNVD
EPSS
0.3%
top 45.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 5
Latest updateDec 16

Description

Out of bounds read in PDFium in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to potentially perform out of bounds memory access via a crafted PDF file. (Chromium security severity: Medium)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages5 packages

CVEListV5google/chrome134.0.6998.35134.0.6998.35
NVDgoogle/chrome< 134.0.6998.35
Debianchromium/chromium< 134.0.6998.35-1~deb12u1+2
Linuxlinux/linux_kernel6.7.06.12.61+2

🔴Vulnerability Details

4
OSV
Bluetooth: hci_sock: Prevent race in socket write iter and sock bind2025-12-16
CVEList
CVE-2025-1918: Out of bounds read in PDFium in Google Chrome prior to 1342025-03-05
GHSA
GHSA-jxvq-qf85-7whf: Out of bounds read in PDFium in Google Chrome prior to 1342025-03-05
OSV
CVE-2025-1918: Out of bounds read in PDFium in Google Chrome prior to 1342025-03-05

📋Vendor Advisories

6
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2025-19182025-03-18
Palo Alto
PAN-SA-2025-0007 Chromium: Monthly Vulnerability Update (March 2025)2025-03-12
Microsoft
Chromium: CVE-2025-1918 Out of bounds read in PDFium2025-03-11
Chrome
Stable Channel Update for Desktop: CVE-2025-19172025-03-04
Debian
CVE-2025-1918: chromium - Out of bounds read in PDFium in Google Chrome prior to 134.0.6998.35 allowed a r...2025
CVE-2025-1918 — Out-of-bounds Read in Google Chrome | cvebase