CVE-2025-6044: Stylus tools appearing after Lock Screen allowing Sensitive Data Exposure
An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the garaged stylus devices allows a physical attacker to bypass the lock screen and access user files by removing the stylus while the device is closed and using the screen capture feature.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-6044?
CVE-2025-6044 is classified as a high-severity vulnerability due to its potential impact on user data security.
How do I fix CVE-2025-6044?
To mitigate CVE-2025-6044, users should update their Google ChromeOS to the latest version released by Google.
Who is affected by CVE-2025-6044?
CVE-2025-6044 affects Google ChromeOS version 16238.64.0 on Lenovo devices.
What type of vulnerability is CVE-2025-6044?
CVE-2025-6044 is an Improper Access Control vulnerability that allows unauthorized access to user files.
What can an attacker do with CVE-2025-6044?
An attacker exploiting CVE-2025-6044 can bypass the lock screen and access user files by manipulating the stylus functionality.