Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed Chrome devices allows a local attacker to disable extensions and access Developer Mode, including loading additional extensions via exploiting vulnerabilities using the ExtHang3r and ExtPrint3r tools.
History

Tue, 17 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 17 Jun 2025 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-276
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Mon, 16 Jun 2025 17:15:00 +0000

Type Values Removed Values Added
Description Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed Chrome devices allows a local attacker to disable extensions and access Developer Mode, including loading additional extensions via exploiting vulnerabilities using the ExtHang3r and ExtPrint3r tools.
Title ChromeOS Extension Disablement and Developer Mode Bypass via ExtHang3r and ExtPrint3r Exploits
References

cve-icon MITRE

Status: PUBLISHED

Assigner: ChromeOS

Published: 2025-06-16T16:56:37.722Z

Updated: 2025-06-17T14:01:39.842Z

Reserved: 2025-06-16T16:50:44.449Z

Link: CVE-2025-6179

cve-icon Vulnrichment

Updated: 2025-06-17T14:00:21.384Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-16T17:15:32.053

Modified: 2025-06-17T20:50:23.507

Link: CVE-2025-6179

cve-icon Redhat

No data.