CVE-2025-1704
published 2025-04-16CVE-2025-1704: ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users with local access to unenroll devices…
PriorityP433medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.20%
10.3th percentile
ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users with local access to unenroll devices
and intercept device management requests via loading components from the unencrypted stateful partition.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome_chrome | — | — | |
| chrome_os | — | — | |
| chromeos | >= 15823.23.0 < 15823.23.0 | 15823.23.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mhjg-qmr3-w2xc: ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 124
ghsa_unreviewed·2025-04-17
CVE-2025-1704 [CRITICAL] CWE-416 GHSA-mhjg-qmr3-w2xc: ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 124
ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 124.0.6367.34 on Chromebooks allows enrolled users with local access to unenroll devices
and intercept device management requests via loading components from the unencrypted stateful partition.
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2025-1704
vendor_chrome·2024-10-29·CVSS 6.5
CVE-2025-1704 [MEDIUM] Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2025-1704
Stable Channel Update for ChromeOS / ChromeOS Flex
CVE-2025-1704
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-04-16
Published