CVE-2025-1121

Privilege escalation in Installer and Recovery image handling in Google ChromeOS 123.0.6312.112 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image.
Configurations

No configuration.

History

07 Mar 2025, 20:15

Type Values Removed Values Added
Summary (en) Privilege escalation in Installer and Recovery image handling in Google ChromeOS 123.0.6312.112 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image. (en) Privilege escalation in Installer and Recovery image handling in Google ChromeOS 123.0.6312.112 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image.
References () https://issuetracker.google.com/issues/336153054 - () https://issuetracker.google.com/issues/336153054 -
CWE CWE-269
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.8

07 Mar 2025, 18:15

Type Values Removed Values Added
References
  • {'url': 'https://issues.chromium.org/issues/b/336153054', 'source': '7f6e188d-c52a-4a19-8674-3c3fa7d1fc7f'}
  • () https://issuetracker.google.com/issues/336153054 -

07 Mar 2025, 02:15

Type Values Removed Values Added
References
  • {'url': 'https://issuetracker.google.com/issues/336153054', 'source': '7f6e188d-c52a-4a19-8674-3c3fa7d1fc7f'}

07 Mar 2025, 01:15

Type Values Removed Values Added
Summary (en) Test CVE description (en) Privilege escalation in Installer and Recovery image handling in Google ChromeOS 123.0.6312.112 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image.

07 Mar 2025, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-07 00:15

Updated : 2025-03-07 20:15


NVD link : CVE-2025-1121

Mitre link : CVE-2025-1121

CVE.ORG link : CVE-2025-1121


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management