CVE-2025-1704
Last modified
CVE-2025-1704 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users with local access to unenroll devices and intercept device management requests via loading components from the unencrypted stateful partition.. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users with local access to unenroll devices and intercept device management requests via loading components from the unencrypted stateful partition.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Chrome Os | 15823.23.0 |
References
- https://issuetracker.google.com/issues/359915523Exploit, Issue Tracking, Mailing List
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-1704?
How severe is CVE-2025-1704?
How do I fix CVE-2025-1704?
Are you affected by CVE-2025-1704?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
