CVE-2025-1121

Privilege escalation in Installer and Recovery image handling in Google ChromeOS version 15786.48.2 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image.
References
Link Resource
https://issues.chromium.org/issues/b/336153054 Issue Tracking Vendor Advisory Broken Link
https://issuetracker.google.com/issues/336153054 Issue Tracking Vendor Advisory
https://issuetracker.google.com/issues/336153054 Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:o:google:chrome_os:15786.48.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-03-07 00:15

Updated : 2025-07-21 16:57


NVD link : CVE-2025-1121

Mitre link : CVE-2025-1121

CVE.ORG link : CVE-2025-1121


JSON object : View

Products Affected

google

  • chrome_os
CWE
CWE-269

Improper Privilege Management