An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the garaged stylus devices allows a physical attacker to bypass the lock screen and access user files by removing the stylus while the device is closed and using the screen capture feature.
History

Wed, 09 Jul 2025 18:45:00 +0000

Type Values Removed Values Added
Description An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on Lenovo devices allows a physical attacker to bypass the lock screen and access user files by removing the stylus while the device is closed and using the screen capture feature. An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the garaged stylus devices allows a physical attacker to bypass the lock screen and access user files by removing the stylus while the device is closed and using the screen capture feature.

Tue, 08 Jul 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 07 Jul 2025 19:15:00 +0000

Type Values Removed Values Added
Description An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on Lenovo devices allows a physical attacker to bypass the lock screen and access user files by removing the stylus while the device is closed and using the screen capture feature.
Title Stylus tools appearing after Lock Screen allowing Sensitive Data Exposure
References

cve-icon MITRE

Status: PUBLISHED

Assigner: ChromeOS

Published: 2025-07-07T18:58:45.456Z

Updated: 2025-07-09T18:35:08.612Z

Reserved: 2025-06-12T21:41:59.445Z

Link: CVE-2025-6044

cve-icon Vulnrichment

Updated: 2025-07-08T14:32:46.277Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-07T19:15:23.920

Modified: 2025-07-08T18:15:43.190

Link: CVE-2025-6044

cve-icon Redhat

No data.