VulnerabilityAnalyzed
CVE-2025-1704
ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users with local access to unenroll devices and intercept device management requests via loading components from the unencrypted stateful…
MEDIUM 6.5EPSS 0.20%
Does this matter?
Lower severity and a low EPSS score (0.20%). Track it; it rarely justifies an emergency change on its own.
Description
ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users with local access to unenroll devices and intercept device management requests via loading components from the unencrypted stateful partition.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.20% probability · 10th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- google/chrome os
- Source
- 7f6e188d-c52a-4a19-8674-3c3fa7d1fc7f
References
- https://issues.chromium.org/issues/b/359915523Broken Link
- https://issuetracker.google.com/issues/359915523Exploit, Issue Tracking, Mailing List
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.