Privilege Escalation in MiniOS in Google ChromeOS (16063.45.2 and potentially others) on enrolled devices allows a local attacker to gain root code execution via exploiting a debug shell (VT3 console) accessible through specific key combinations during developer mode entry and MiniOS access, even when developer mode is blocked by device policy or Firmware Write Protect (FWMP).
History

Mon, 16 Jun 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 16 Jun 2025 17:00:00 +0000

Type Values Removed Values Added
Description Privilege Escalation in MiniOS in Google ChromeOS (16063.45.2 and potentially others) on enrolled devices allows a local attacker to gain root code execution via exploiting a debug shell (VT3 console) accessible through specific key combinations during developer mode entry and MiniOS access, even when developer mode is blocked by device policy or Firmware Write Protect (FWMP).
Title ChromeOS MiniOS Root Code Execution Bypass While Dev Mode Blocked
References

cve-icon MITRE

Status: PUBLISHED

Assigner: ChromeOS

Published: 2025-06-16T16:43:44.191Z

Updated: 2025-06-17T03:55:13.297Z

Reserved: 2025-06-16T16:30:47.684Z

Link: CVE-2025-6177

cve-icon Vulnrichment

Updated: 2025-06-16T18:02:47.009Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-16T17:15:31.813

Modified: 2025-06-17T20:50:23.507

Link: CVE-2025-6177

cve-icon Redhat

No data.