VDB
CVE-2025-6177
CVE-2025-6177
PUBLISHED
CVSS 7.400000095367432 HIGH
Privilege Escalation in MiniOS in Google ChromeOS (16063.45.2 and potentially others) on enrolled devices allows a local attacker to gain root code execution via exploiting a debug shell (VT3 console) accessible through specific key combinations during developer mode entry and MiniOS access, even when developer mode is blocked by device policy or Firmware Write Protect (FWMP).
EPSS 0.09% · 0.4th percentile
Risk Scores
CVSS 3.1
7.400000095367432
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.09%
0.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ChromeOS | 16063.45.2 | |
| chrome_os | 16063.45.2 |
Timeline
- Jun 16, 2025 Coalition ESS Score
- Jun 16, 2025 Coalition ESS Score
- Jun 16, 2025 CVE Published
- Jun 16, 2025 PoC Published
- Jun 17, 2025 EPSS Score
- Jun 17, 2025 PoC Published
- Jun 18, 2025 Coalition ESS Score
- Jun 27, 2025 EPSS Score
- Jul 2, 2025 Coalition ESS Score
- Jul 8, 2025 EPSS Score
- Jul 18, 2025 EPSS Score
- Jul 21, 2025 Coalition ESS Score