ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users with local access to unenroll devices and intercept device management requests via loading components from the unencrypted stateful partition.
History

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00026}

epss

{'score': 0.00024}


Fri, 11 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome Os
CPEs cpe:2.3:o:google:chrome_os:15823.23.0:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome Os

Tue, 06 May 2025 01:15:00 +0000

Type Values Removed Values Added
Description ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 124.0.6367.34 on Chromebooks allows enrolled users with local access to unenroll devices and intercept device management requests via loading components from the unencrypted stateful partition. ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users with local access to unenroll devices and intercept device management requests via loading components from the unencrypted stateful partition.

Thu, 17 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 00:30:00 +0000

Type Values Removed Values Added
Title ComponentInstaller Vulnerability Allowing Chromebook Unenrollment and Potential Device Management Key Interception in ChromeOS

Wed, 16 Apr 2025 23:15:00 +0000

Type Values Removed Values Added
Description ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 124.0.6367.34 on Chromebooks allows enrolled users with local access to unenroll devices and intercept device management requests via loading components from the unencrypted stateful partition.
Title ComponentInstaller Vulnerability Allowing Chromebook Unenrollment and Potential Device Management Key Interception in ChromeOS
References

cve-icon MITRE

Status: PUBLISHED

Assigner: ChromeOS

Published: 2025-04-16T23:06:28.279Z

Updated: 2025-05-08T19:15:06.471Z

Reserved: 2025-02-25T23:19:38.958Z

Link: CVE-2025-1704

cve-icon Vulnrichment

Updated: 2025-04-17T13:31:30.811Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-16T23:15:44.937

Modified: 2025-07-11T14:15:07.663

Link: CVE-2025-1704

cve-icon Redhat

No data.