← Back

CVE-2025-1704

nvd nist
Published: Apr 16, 2025Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users with local access to unenroll devices and intercept device management requests via loading components from the unencrypted stateful partition.

Affected (1)

Products: Google: Chrome Os
1 product
Chrome Os
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 15823.23.0

References (2)

Source: 7f6e188d-c52a-4a19-8674-3c3fa7d1fc7f
Broken Link
Source: 7f6e188d-c52a-4a19-8674-3c3fa7d1fc7f
ExploitIssue TrackingMailing List

Timeline

No history available yet.