CVE-2025-1704 – Google ChromeOS ComponentInstaller Unenrollment and Device Management Request Interception Vulnerability

The following table lists the changes that have been made to the
CVE-2025-1704 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by 7f6e188d-c52a-4a19-8674-3c3fa7d1fc7f

    Apr. 16, 2025

    Action Type Old Value New Value
    Added Description ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 124.0.6367.34 on Chromebooks allows enrolled users with local access to unenroll devices
    and intercept device management requests via loading components from the unencrypted stateful partition.
    Added Reference https://issues.chromium.org/issues/b/359915523
    Added Reference https://issuetracker.google.com/issues/359915523
Share the Post:

Related Posts