- Description
- Privilege escalation in Installer and Recovery image handling in Google ChromeOS version 15786.48.2 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image.
- Source
- 7f6e188d-c52a-4a19-8674-3c3fa7d1fc7f
- NVD status
- Analyzed
- Products
- chrome_os
CVSS 3.1
- Type
- Secondary
- Base score
- 6.8
- Impact score
- 5.9
- Exploitability score
- 0.9
- Vector string
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- MEDIUM
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-269
- Hype score
- Not currently trending
🔴 #Google ChromeOS, Privilege Escalation, #CVE-2025-1121 (Critical) https://t.co/EUwOS1vRut
@dailycve
21 Jul 2025
15 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-1121 ChromeOS 123.0.6312.112 Local Privilege Escalation via Recovery Image Manipulation https://t.co/SfCFXqikHp
@VulmonFeeds
7 Mar 2025
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-1121 Privilege escalation in Installer and Recovery image handling in Google ChromeOS 123.0.6312.112 on device allows an attacker with physical access to gain root code exe… https://t.co/uCrm1XMTnG
@CVEnew
7 Mar 2025
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:google:chrome_os:15786.48.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D681E31E-CF4E-4853-9837-77B14FF419E8"
}
],
"operator": "OR"
}
]
}
]