DNS Leak in Native System VPN in Google ChromeOS Dev Channel on ChromeOS 129.0.6668.36 allows network observers to expose plaintext DNS queries via failure to properly tunnel DNS traffic during VPN state transitions.
History

Thu, 17 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1319
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 00:30:00 +0000

Type Values Removed Values Added
Title DNS Leak Vulnerability in ChromeOS Android Subsystem VPN Implementation Due to Unstable WireGuard Integration

Wed, 16 Apr 2025 23:15:00 +0000

Type Values Removed Values Added
Description DNS Leak in Native System VPN in Google ChromeOS Dev Channel on ChromeOS 129.0.6668.36 allows network observers to expose plaintext DNS queries via failure to properly tunnel DNS traffic during VPN state transitions.
Title DNS Leak Vulnerability in ChromeOS Android Subsystem VPN Implementation Due to Unstable WireGuard Integration
References

cve-icon MITRE

Status: PUBLISHED

Assigner: ChromeOS

Published:

Updated: 2025-04-17T15:50:50.567Z

Reserved: 2025-02-21T21:30:53.937Z

Link: CVE-2025-1566

cve-icon Vulnrichment

Updated: 2025-04-17T15:14:28.569Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-16T23:15:44.767

Modified: 2025-04-17T20:21:48.243

Link: CVE-2025-1566

cve-icon Redhat

No data.