ID |
CVE-2025-6177
|
Sažetak |
Privilege Escalation in MiniOS in Google ChromeOS (16063.45.2 and potentially others) on enrolled devices allows a local attacker to gain root code execution via exploiting a debug shell (VT3 console) accessible through specific key combinations during developer mode entry and MiniOS access, even when developer mode is blocked by device policy or Firmware Write Protect (FWMP). |
Reference |
|
CVSS |
Base: | 7.4 |
Impact: | 5.9 |
Exploitability: | 1.4 |
|
Pristup |
Vektor | Složenost | Autentikacija |
LOCAL |
HIGH |
NONE |
|
Impact |
Povjerljivost | Cjelovitost | Dostupnost |
HIGH |
HIGH |
HIGH |
|
CVSS vektor |
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Zadnje važnije ažuriranje |
16-06-2025 - 18:15 |
Objavljeno |
16-06-2025 - 17:15 |