Privilege escalation in Installer and Recovery image handling in Google ChromeOS 123.0.6312.112 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image.
History

Fri, 07 Mar 2025 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Mar 2025 19:30:00 +0000

Type Values Removed Values Added
Description Privilege escalation in Installer and Recovery image handling in Google ChromeOS 123.0.6312.112 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image. Privilege escalation in Installer and Recovery image handling in Google ChromeOS 123.0.6312.112 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image.
Title Privilege Escalation via modified recovery mage Privilege Escalation via modified recovery Image

Fri, 07 Mar 2025 18:45:00 +0000

Type Values Removed Values Added
References

Fri, 07 Mar 2025 18:15:00 +0000

Type Values Removed Values Added
References

Fri, 07 Mar 2025 02:45:00 +0000

Type Values Removed Values Added
References

Fri, 07 Mar 2025 01:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via modified recovery mage

Fri, 07 Mar 2025 00:30:00 +0000

Type Values Removed Values Added
Description Test CVE description Privilege escalation in Installer and Recovery image handling in Google ChromeOS 123.0.6312.112 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image.

Fri, 07 Mar 2025 00:00:00 +0000

Type Values Removed Values Added
Description Test CVE description
References

cve-icon MITRE

Status: PUBLISHED

Assigner: ChromeOS

Published: 2025-03-06T23:49:03.219Z

Updated: 2025-03-07T19:39:15.501Z

Reserved: 2025-02-07T18:26:21.569Z

Link: CVE-2025-1121

cve-icon Vulnrichment

Updated: 2025-03-07T19:38:47.936Z

cve-icon NVD

Status : Received

Published: 2025-03-07T00:15:34.360

Modified: 2025-03-07T20:15:37.407

Link: CVE-2025-1121

cve-icon Redhat

No data.