CVE-2025-1704 Details
Description
ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users with local access to unenroll devices and intercept device management requests via loading components from the unencrypted stateful partition.
A vulnerability exists in the ComponentInstaller of Google ChromeOS version 15823.23.0 on Chromebooks. This issue allows enrolled users with local access to unenroll devices and intercept device management requests by loading components from the unencrypted stateful partition. The vulnerability arises because ComponentInstaller now reads from an unencrypted stateful partition, a change made in a recent update. This modification can be exploited to alter important metadata components, potentially disrupting device management processes.
The vulnerability has been fixed in the latest version of ChromeOS. Users should ensure their devices are updated to the most recent version.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 17, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://issues.chromium.org/issues/b/359915523 | ChromeOS | Broken Link |
| https://issuetracker.google.com/issues/359915523 | ChromeOS | ExploitIssue TrackingMailing List |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| google chrome os | 15823.23.0 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | ChromeOS |
| Jul 11, 2025 | Initial Analysis | [email protected] |
| May 6, 2025 | CVE Modified | ChromeOS |
| Apr 17, 2025 | CVE Modified | CISA-ADP |
| Apr 17, 2025 | CVE Modified | CISA-ADP |
| Apr 16, 2025 | New CVE Received | ChromeOS |