VYPR
Medium severity6.8NVD Advisory· Published Mar 7, 2025· Updated Jun 17, 2026

CVE-2025-1121

CVE-2025-1121

Description

Privilege escalation in Installer and Recovery image handling in Google ChromeOS version 15786.48.2 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image.

Affected products

3
  • Google/ChromeOS2 versions
    cpe:2.3:o:google:chrome_os:15786.48.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:google:chrome_os:15786.48.0:*:*:*:*:*:*:*
    • (no CPE)range: 15786.48.2
  • Google/Chromecpe-rescue
    Range: 15786.48.2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.