CVE-2025-6044
published 2025-07-07CVE-2025-6044: An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the garaged stylus devices allows a physical…
PriorityP429medium6.1CVSS 3.1
AVPACLPRNUINSUCHIHAN
EPSS
0.11%
1.8th percentile
An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the garaged stylus devices allows a physical attacker to bypass the lock screen and access user files by removing the stylus while the device is closed and using the screen capture feature.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome_chrome | — | — | |
| chrome_os | — | — | |
| chromeos | >= 16238.64.0 < 16238.64.0 | 16238.64.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Chanel Update for ChromeOS / ChromeOS-Flex: CVE-2025-6044
vendor_chrome·2025-07-23·CVSS 6.1
CVE-2025-6044 [MEDIUM] Stable Chanel Update for ChromeOS / ChromeOS-Flex: CVE-2025-6044
Stable Chanel Update for ChromeOS / ChromeOS-Flex
CVE-2025-6044
GHSA
GHSA-p4mw-xc4p-683j: An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238
ghsa_unreviewed·2025-07-07
CVE-2025-6044 [MEDIUM] CWE-287 GHSA-p4mw-xc4p-683j: An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238
An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on Lenovo devices allows a physical attacker to bypass the lock screen and access user files by removing the stylus while the device is closed and using the screen capture feature.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-07-07
Published