VDB

CVE-2025-6177

CVE-2025-6177 PUBLISHED CVSS 7.400000095367432 HIGH

Privilege Escalation in MiniOS in Google ChromeOS (16063.45.2 and potentially others) on enrolled devices allows a local attacker to gain root code execution via exploiting a debug shell (VT3 console) accessible through specific key combinations during developer mode entry and MiniOS access, even when developer mode is blocked by device policy or Firmware Write Protect (FWMP).

EPSS 0.09% · 0.4th percentile

Risk Scores

CVSS 3.1
7.400000095367432
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.09%
0.4th percentile

Affected Products

VendorProductVersions
GoogleChromeOS16063.45.2
googlechrome_os16063.45.2

Timeline

  • Jun 16, 2025 Coalition ESS Score
  • Jun 16, 2025 Coalition ESS Score
  • Jun 16, 2025 CVE Published
  • Jun 16, 2025 PoC Published
  • Jun 17, 2025 EPSS Score
  • Jun 17, 2025 PoC Published
  • Jun 18, 2025 Coalition ESS Score
  • Jun 27, 2025 EPSS Score
  • Jul 2, 2025 Coalition ESS Score
  • Jul 8, 2025 EPSS Score
  • Jul 18, 2025 EPSS Score
  • Jul 21, 2025 Coalition ESS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›