CVE-2025-1704

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 16, 2025
Updated: May 6, 2025
CWE ID 416

Summary

CVE-2025-1704 is a vulnerability affecting Google ChromeOS 15823.23.0 on Chromebooks. It involves a modification in the ComponentInstaller component, which enables enrolled users with local access to unenroll devices and intercept device management requests. By loading components from the unencrypted stateful partition, attackers can exploit this vulnerability to gain unauthorized control over the device management process. This issue poses a significant risk to the security and configuration management of Chromebooks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share