VYPR
High severity7.5NVD Advisory· Published Apr 16, 2025· Updated Jun 17, 2026

CVE-2025-1566

CVE-2025-1566

Description

DNS Leak in Native System VPN in Google ChromeOS Dev Channel on ChromeOS 16002.23.0 allows network observers to expose plaintext DNS queries via failure to properly tunnel DNS traffic during VPN state transitions.

Affected products

3
  • Google/ChromeOS2 versions
    cpe:2.3:o:google:chrome_os:16002.23.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:google:chrome_os:16002.23.0:*:*:*:*:*:*:*
    • (no CPE)range: = 16002.23.0
  • Google/Chromecpe-rescue
    Range: 16002.23.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.