First published: Thu Mar 06 2025(Updated: )
Privilege escalation in Installer and Recovery image handling in Google ChromeOS 123.0.6312.112 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image.
Credit: 7f6e188d-c52a-4a19-8674-3c3fa7d1fc7f
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome OS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-1121 is classified as high due to its potential for privilege escalation.
To fix CVE-2025-1121, ensure you have the latest updates for Google ChromeOS installed that address this vulnerability.
CVE-2025-1121 allows attackers with physical access to escalate privileges and potentially unenroll enterprise-managed devices.
All users of Google ChromeOS version 123.0.6312.112 and earlier who have physical access to their devices are affected by CVE-2025-1121.
No, CVE-2025-1121 requires physical access to the device to exploit and gain root code execution.