CVE-2025-1292 – Google ChromeOS TPM2 Reference Library Out-of-Bounds Write (Persistence and OS Verification Bypass)

The following table lists the changes that have been made to the
CVE-2025-1292 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by 7f6e188d-c52a-4a19-8674-3c3fa7d1fc7f

    Apr. 15, 2025

    Action Type Old Value New Value
    Added Description Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain persistence and
    bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process.
    Added Reference https://issues.chromium.org/issues/b/324336238
    Added Reference https://issuetracker.google.com/issues/324336238
Share the Post:

Related Posts