ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 124.0.6367.34 on Chromebooks allows enrolled users with local access to unenroll devices and intercept device management requests via loading components from the unencrypted stateful partition.
History

Thu, 17 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 00:30:00 +0000

Type Values Removed Values Added
Title ComponentInstaller Vulnerability Allowing Chromebook Unenrollment and Potential Device Management Key Interception in ChromeOS

Wed, 16 Apr 2025 23:15:00 +0000

Type Values Removed Values Added
Description ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 124.0.6367.34 on Chromebooks allows enrolled users with local access to unenroll devices and intercept device management requests via loading components from the unencrypted stateful partition.
Title ComponentInstaller Vulnerability Allowing Chromebook Unenrollment and Potential Device Management Key Interception in ChromeOS
References

cve-icon MITRE

Status: PUBLISHED

Assigner: ChromeOS

Published:

Updated: 2025-04-17T15:48:28.527Z

Reserved: 2025-02-25T23:19:38.958Z

Link: CVE-2025-1704

cve-icon Vulnrichment

Updated: 2025-04-17T13:31:30.811Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-16T23:15:44.937

Modified: 2025-04-17T20:21:48.243

Link: CVE-2025-1704

cve-icon Redhat

No data.