CVE-2025-1121: Privilege Escalation via modified recovery Image
Privilege escalation in Installer and Recovery image handling in Google ChromeOS version 15786.48.2 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1121?
The severity of CVE-2025-1121 is classified as high due to its potential for privilege escalation.
How do I fix CVE-2025-1121?
To fix CVE-2025-1121, ensure you have the latest updates for Google ChromeOS installed that address this vulnerability.
What impact does CVE-2025-1121 have on Google ChromeOS?
CVE-2025-1121 allows attackers with physical access to escalate privileges and potentially unenroll enterprise-managed devices.
Who is affected by CVE-2025-1121?
All users of Google ChromeOS version 123.0.6312.112 and earlier who have physical access to their devices are affected by CVE-2025-1121.
Is CVE-2025-1121 a remote exploit?
No, CVE-2025-1121 requires physical access to the device to exploit and gain root code execution.