VDB

CVE-2025-1704

CVE-2025-1704 PUBLISHED CVSS 9.800000190734863 CRITICAL

ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 124.0.6367.34 on Chromebooks allows enrolled users with local access to unenroll devices and intercept device management requests via loading components from the unencrypted stateful partition.

EPSS 0.20% · 10.0th percentile

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.20%
10.0th percentile

Affected Products

VendorProductVersions
googlechrome_os15823.23.0
GoogleChromeOS15823.23.0

Timeline

  • Feb 25, 2025 CVE ID Reserved
  • Apr 16, 2025 CVE Published
  • Apr 17, 2025 EPSS Score
  • Apr 17, 2025 PoC Published
  • Apr 17, 2025 PoC Published
  • Apr 30, 2025 EPSS Score
  • May 8, 2025 CVE Updated
  • May 12, 2025 EPSS Score
  • May 25, 2025 EPSS Score
  • Jun 6, 2025 EPSS Score
  • Jun 13, 2025 Coalition ESS Score
  • Jun 19, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›