We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-6177

ChromeOS MiniOS Root Code Execution Bypass While Dev Mode Blocked



Description

Privilege Escalation in MiniOS in Google ChromeOS (16063.45.2 and potentially others) on enrolled devices allows a local attacker to gain root code execution via exploiting a debug shell (VT3 console) accessible through specific key combinations during developer mode entry and MiniOS access, even when developer mode is blocked by device policy or Firmware Write Protect (FWMP).

Reserved 2025-06-16 | Published 2025-06-16 | Updated 2025-06-16 | Assigner ChromeOS

Problem types

Privilege Escalation

Product status

Default status
unaffected

16063.45.2
affected

References

issuetracker.google.com/issues/382540412

issues.chromium.org/issues/b/382540412

cve.org (CVE-2025-6177)

nvd.nist.gov (CVE-2025-6177)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-6177

Support options

Helpdesk Chat, Email, Knowledgebase