Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker with root access to gain persistence and
Bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process.
Metrics
Affected Vendors & Products
References
History
Mon, 06 Oct 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Google
Google chrome Google chrome Os |
|
CPEs | cpe:2.3:a:google:chrome:122.0.6261.132:*:*:*:*:*:*:* cpe:2.3:o:google:chrome_os:-:*:*:*:*:*:*:* |
|
Vendors & Products |
Google
Google chrome Google chrome Os |
Tue, 06 May 2025 01:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain persistence and Bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process. | Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker with root access to gain persistence and Bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process. |
Thu, 17 Apr 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-787 | |
Metrics |
cvssV3_1
|
Thu, 17 Apr 2025 00:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain persistence and bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process. | Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain persistence and Bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process. |
Wed, 16 Apr 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | TPM2 Out-Of-Bounds Write Leading to Potential Operating System Verification Bypass in ChromeOS |
Tue, 15 Apr 2025 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain persistence and bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process. | |
Title | TPM2 Out-Of-Bounds Write Leading to Potential Operating System Verification Bypass in ChromeOS | |
References |
|

Status: PUBLISHED
Assigner: ChromeOS
Published: 2025-04-15T19:51:23.127Z
Updated: 2025-05-08T19:15:05.948Z
Reserved: 2025-02-07T18:38:22.520Z
Link: CVE-2025-1122

Updated: 2025-04-15T20:43:15.358Z

Status : Analyzed
Published: 2025-04-15T20:15:38.317
Modified: 2025-10-06T16:56:59.303
Link: CVE-2025-1122

No data.