Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker with root access to gain persistence and
Bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process.
Metrics
Affected Vendors & Products
References
History
Tue, 06 May 2025 01:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain persistence and Bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process. | Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker with root access to gain persistence and Bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process. |
Thu, 17 Apr 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-787 | |
Metrics |
cvssV3_1
|
Thu, 17 Apr 2025 00:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain persistence and bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process. | Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain persistence and Bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process. |
Wed, 16 Apr 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | TPM2 Out-Of-Bounds Write Leading to Potential Operating System Verification Bypass in ChromeOS |
Tue, 15 Apr 2025 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain persistence and bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process. | |
Title | TPM2 Out-Of-Bounds Write Leading to Potential Operating System Verification Bypass in ChromeOS | |
References |
|

Status: PUBLISHED
Assigner: ChromeOS
Published: 2025-04-15T19:51:23.127Z
Updated: 2025-05-08T19:15:05.948Z
Reserved: 2025-02-07T18:38:22.520Z
Link: CVE-2025-1122

Updated: 2025-04-15T20:43:15.358Z

Status : Awaiting Analysis
Published: 2025-04-15T20:15:38.317
Modified: 2025-05-06T01:15:49.777
Link: CVE-2025-1122

No data.