CVE-2025-1566
published 2025-04-16CVE-2025-1566: DNS Leak in Native System VPN in Google ChromeOS Dev Channel on ChromeOS 16002.23.0 allows network observers to expose plaintext DNS queries via failure to…
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.20%
9.6th percentile
DNS Leak in Native System VPN in Google ChromeOS Dev Channel on ChromeOS 16002.23.0 allows network observers to expose plaintext DNS queries via failure to properly tunnel DNS traffic during VPN state transitions.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome_chrome | — | — | |
| chrome_os | — | — | |
| chromeos | >= 16002.23.0 < 16002.23.0 | 16002.23.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex - M133: CVE-2025-1566
vendor_chrome·2025-02-21·CVSS 7.5
CVE-2025-1566 [HIGH] Stable Channel Update for ChromeOS / ChromeOS Flex - M133: CVE-2025-1566
Stable Channel Update for ChromeOS / ChromeOS Flex - M133
CVE-2025-1566
GHSA
GHSA-gm22-hqvw-7j52: DNS Leak in Native System VPN in Google ChromeOS Dev Channel on ChromeOS 129
ghsa_unreviewed·2025-04-17
CVE-2025-1566 [HIGH] CWE-1319 GHSA-gm22-hqvw-7j52: DNS Leak in Native System VPN in Google ChromeOS Dev Channel on ChromeOS 129
DNS Leak in Native System VPN in Google ChromeOS Dev Channel on ChromeOS 129.0.6668.36 allows network observers to expose plaintext DNS queries via failure to properly tunnel DNS traffic during VPN state transitions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-04-16
Published