VDB
CVE-2025-1704
CVE-2025-1704
PUBLISHED
CVSS 9.800000190734863 CRITICAL
ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 124.0.6367.34 on Chromebooks allows enrolled users with local access to unenroll devices and intercept device management requests via loading components from the unencrypted stateful partition.
EPSS 0.20% · 10.0th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.20%
10.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| chrome_os | 15823.23.0 | |
| ChromeOS | 15823.23.0 |
Timeline
- Feb 25, 2025 CVE ID Reserved
- Apr 16, 2025 CVE Published
- Apr 17, 2025 EPSS Score
- Apr 17, 2025 PoC Published
- Apr 17, 2025 PoC Published
- Apr 30, 2025 EPSS Score
- May 8, 2025 CVE Updated
- May 12, 2025 EPSS Score
- May 25, 2025 EPSS Score
- Jun 6, 2025 EPSS Score
- Jun 13, 2025 Coalition ESS Score
- Jun 19, 2025 EPSS Score