We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-34091

Chrome Cookie Encryption Bypass via Padding Oracle Attack on AppBound Encryption



Description

A padding oracle vulnerability exists in Google Chrome’s AppBound cookie encryption mechanism due to observable decryption failure behavior in Windows Event Logs when handling malformed ciphertext in SYSTEM-DPAPI-encrypted blobs. A local attacker can repeatedly send malformed ciphertexts to the Chrome elevation service and distinguish between padding and MAC errors, enabling a padding oracle attack. This allows partial decryption of the SYSTEM-DPAPI layer and eventual recovery of the user-DPAPI encrypted cookie key, which is trivially decrypted by the attacker’s own context. This issue undermines the core purpose of AppBound Encryption by enabling low-privileged cookie theft through cryptographic misuse and verbose error feedback. Confirmed in Google Chrome with AppBound Encryption enabled. Other Chromium-based browsers may be affected if they implement similar COM-based encryption mechanisms. This behavior arises from a combination of Chrome’s AppBound implementation and the way Microsoft Windows DPAPI reports decryption failures via Event Logs. As such, the vulnerability relies on cryptographic behavior and error visibility in all supported versions of Windows.

Reserved 2025-04-15 | Published 2025-07-02 | Updated 2025-07-03 | Assigner VulnCheck


HIGH: 8.8CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Problem types

CWE-203 Observable Discrepancy

CWE-209 Generation of Error Message Containing Sensitive Information

Product status

Default status
unknown

127 before 129
affected

Credits

Ari Novick of CyberArk Labs finder

References

www.cyberark.com/...ng-up-chromes-appbound-cookie-encryption technical-description third-party-advisory

vulncheck.com/...es/google-chrome-appbound-cookie-encryption third-party-advisory

cve.org (CVE-2025-34091)

nvd.nist.gov (CVE-2025-34091)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-34091

Support options

Helpdesk Chat, Email, Knowledgebase