Privilege escalation in Installer and Recovery image handling in Google ChromeOS version 15786.48.2 on device allows an attacker with physical access to gain root code
execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-7378 Privilege escalation in Installer and Recovery image handling in Google ChromeOS version 15786.48.2 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 22 Jul 2025 02:00:00 +0900

Type Values Removed Values Added
First Time appeared Google
Google chrome Os
CPEs cpe:2.3:o:google:chrome_os:15786.48.0:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome Os

Tue, 06 May 2025 10:15:00 +0900

Type Values Removed Values Added
Description Privilege escalation in Installer and Recovery image handling in Google ChromeOS 123.0.6312.112 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image. Privilege escalation in Installer and Recovery image handling in Google ChromeOS version 15786.48.2 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image.
Title Privilege Escalation via modified recovery Image
References

Sat, 08 Mar 2025 05:15:00 +0900

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 08 Mar 2025 04:30:00 +0900

Type Values Removed Values Added
Description Privilege escalation in Installer and Recovery image handling in Google ChromeOS 123.0.6312.112 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image. Privilege escalation in Installer and Recovery image handling in Google ChromeOS 123.0.6312.112 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image.
Title Privilege Escalation via modified recovery mage Privilege Escalation via modified recovery Image

Sat, 08 Mar 2025 03:45:00 +0900

Type Values Removed Values Added
References

Sat, 08 Mar 2025 03:15:00 +0900

Type Values Removed Values Added
References

Fri, 07 Mar 2025 11:45:00 +0900

Type Values Removed Values Added
References

Fri, 07 Mar 2025 10:30:00 +0900

Type Values Removed Values Added
Title Privilege Escalation via modified recovery mage

Fri, 07 Mar 2025 09:30:00 +0900

Type Values Removed Values Added
Description Test CVE description Privilege escalation in Installer and Recovery image handling in Google ChromeOS 123.0.6312.112 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image.

Fri, 07 Mar 2025 09:00:00 +0900

Type Values Removed Values Added
Description Test CVE description
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ChromeOS

Published:

Updated: 2025-05-08T19:15:05.506Z

Reserved: 2025-02-07T18:26:21.569Z

Link: CVE-2025-1121

cve-icon Vulnrichment

Updated: 2025-03-07T19:38:47.936Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-07T00:15:34.360

Modified: 2025-07-21T16:57:28.230

Link: CVE-2025-1121

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses