CVE-2025-1566 – “Google ChromeOS Native System VPN DNS Leak Vulnerability”

The following table lists the changes that have been made to the
CVE-2025-1566 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by 7f6e188d-c52a-4a19-8674-3c3fa7d1fc7f

    Apr. 16, 2025

    Action Type Old Value New Value
    Added Description DNS Leak in Native System VPN in Google ChromeOS Dev Channel on ChromeOS 129.0.6668.36 allows network observers to expose plaintext DNS queries via failure to properly tunnel DNS traffic during VPN state transitions.
    Added Reference https://issues.chromium.org/issues/b/342802975
    Added Reference https://issuetracker.google.com/issues/342802975
Share the Post:

Related Posts