Severity
6.7MEDIUM
EPSS
0.0%
top 98.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 15
Latest updateOct 28

Description

Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker with root access to gain persistence and Bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5google/chromeos15753.50.015753.50.0
NVDgoogle/chrome122.0.6261.132

🔴Vulnerability Details

3
GHSA
ImageMagick has Integer Overflow in BMP Decoder (ReadBMP)2025-10-28
GHSA
GHSA-j93w-j7jm-5c8h: Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 1222025-04-15
CVEList
CVE-2025-1122: Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 157532025-04-15
CVE-2025-1122 (MEDIUM CVSS 6.7) | Out-Of-Bounds Write in TPM2 Referen | cvebase.io