CVE-2025-6177: ChromeOS MiniOS Root Code Execution Bypass While Dev Mode Blocked
Privilege Escalation in MiniOS in Google ChromeOS (16063.45.2 and potentially others) on enrolled devices allows a local attacker to gain root code execution via exploiting a debug shell (VT3 console) accessible through specific key combinations during developer mode entry and MiniOS access, even when developer mode is blocked by device policy or Firmware Write Protect (FWMP).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6177?
CVE-2025-6177 is classified as a privilege escalation vulnerability in MiniOS affecting Google ChromeOS.
How do I fix CVE-2025-6177?
To fix CVE-2025-6177, ensure your Google ChromeOS is updated to the latest version, incorporating security patches.
Who is affected by CVE-2025-6177?
CVE-2025-6177 affects enrolled devices running specific versions of Google ChromeOS, particularly those in developer mode.
What type of attack does CVE-2025-6177 enable?
CVE-2025-6177 allows a local attacker to gain root code execution through a debug shell during developer mode access.
When was CVE-2025-6177 disclosed?
CVE-2025-6177 was disclosed in relation to specific versions of Google ChromeOS including 16063.45.2.