CWE
269
Advisory Published
Updated

CVE-2025-1121: Privilege Escalation via modified recovery Image

First published: Thu Mar 06 2025(Updated: )

Privilege escalation in Installer and Recovery image handling in Google ChromeOS 123.0.6312.112 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image.

Credit: 7f6e188d-c52a-4a19-8674-3c3fa7d1fc7f

Affected SoftwareAffected VersionHow to fix
Google Chrome OS

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2025-1121?

    The severity of CVE-2025-1121 is classified as high due to its potential for privilege escalation.

  • How do I fix CVE-2025-1121?

    To fix CVE-2025-1121, ensure you have the latest updates for Google ChromeOS installed that address this vulnerability.

  • What impact does CVE-2025-1121 have on Google ChromeOS?

    CVE-2025-1121 allows attackers with physical access to escalate privileges and potentially unenroll enterprise-managed devices.

  • Who is affected by CVE-2025-1121?

    All users of Google ChromeOS version 123.0.6312.112 and earlier who have physical access to their devices are affected by CVE-2025-1121.

  • Is CVE-2025-1121 a remote exploit?

    No, CVE-2025-1121 requires physical access to the device to exploit and gain root code execution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203