execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-7378 | Privilege escalation in Installer and Recovery image handling in Google ChromeOS version 15786.48.2 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image. |
Mon, 21 Jul 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google chrome Os |
|
| CPEs | cpe:2.3:o:google:chrome_os:15786.48.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Google
Google chrome Os |
Tue, 06 May 2025 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Privilege escalation in Installer and Recovery image handling in Google ChromeOS 123.0.6312.112 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image. | Privilege escalation in Installer and Recovery image handling in Google ChromeOS version 15786.48.2 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image. |
| Title | Privilege Escalation via modified recovery Image | |
| References |
|
Fri, 07 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 | |
| Metrics |
cvssV3_1
|
Fri, 07 Mar 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Privilege escalation in Installer and Recovery image handling in Google ChromeOS 123.0.6312.112 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image. | Privilege escalation in Installer and Recovery image handling in Google ChromeOS 123.0.6312.112 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image. |
| Title | Privilege Escalation via modified recovery mage | Privilege Escalation via modified recovery Image |
Fri, 07 Mar 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 07 Mar 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 07 Mar 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 07 Mar 2025 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Privilege Escalation via modified recovery mage |
Fri, 07 Mar 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Test CVE description | Privilege escalation in Installer and Recovery image handling in Google ChromeOS 123.0.6312.112 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image. |
Fri, 07 Mar 2025 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Test CVE description | |
| References |
|
Status: PUBLISHED
Assigner: ChromeOS
Published:
Updated: 2025-05-08T19:15:05.506Z
Reserved: 2025-02-07T18:26:21.569Z
Link: CVE-2025-1121
Updated: 2025-03-07T19:38:47.936Z
Status : Analyzed
Published: 2025-03-07T00:15:34.360
Modified: 2025-07-21T16:57:28.230
Link: CVE-2025-1121
No data.
OpenCVE Enrichment
No data.
EUVD