← Back

CVE-2025-1292

nvd nist
Published: Apr 15, 2025Modified: Oct 6, 2025

JSON object

Loading...
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain persistence and bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process.

Affected (1)

Products: Google: Chrome
1 product
Chrome
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 122.0.6261.132
Running on/withPlatform Versions
Google
Chrome Os
All versions

References (2)

Source: 7f6e188d-c52a-4a19-8674-3c3fa7d1fc7f
Broken Link
Source: 7f6e188d-c52a-4a19-8674-3c3fa7d1fc7f
ExploitIssue Tracking

Timeline

No history available yet.