Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-20310 | An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the garaged stylus devices allows a physical attacker to bypass the lock screen and access user files by removing the stylus while the device is closed and using the screen capture feature. |
Fri, 03 Oct 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google chrome Os |
|
| CPEs | cpe:2.3:o:google:chrome_os:16238.64.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Google
Google chrome Os |
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 09 Jul 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Stylus tools appearing after Lock Screen allowing Sensitive Data Exposure |
Wed, 09 Jul 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on Lenovo devices allows a physical attacker to bypass the lock screen and access user files by removing the stylus while the device is closed and using the screen capture feature. | An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the garaged stylus devices allows a physical attacker to bypass the lock screen and access user files by removing the stylus while the device is closed and using the screen capture feature. |
Tue, 08 Jul 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-287 | |
| Metrics |
cvssV3_1
|
Mon, 07 Jul 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on Lenovo devices allows a physical attacker to bypass the lock screen and access user files by removing the stylus while the device is closed and using the screen capture feature. | |
| Title | Stylus tools appearing after Lock Screen allowing Sensitive Data Exposure | |
| References |
|
Status: PUBLISHED
Assigner: ChromeOS
Published:
Updated: 2025-07-09T18:35:08.612Z
Reserved: 2025-06-12T21:41:59.445Z
Link: CVE-2025-6044
Updated: 2025-07-08T14:32:46.277Z
Status : Analyzed
Published: 2025-07-07T19:15:23.920
Modified: 2025-10-03T15:54:42.200
Link: CVE-2025-6044
No data.
OpenCVE Enrichment
No data.
EUVD