issues.chromium.org
https://issues.chromium.org/issues/b/324336238 CVE-2025-1122
MEDIUM
Record summary
CVE-2025-1122 has a selected CVSS score of 6.7 (medium).
Description
Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker with root access to gain persistence and Bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 15, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ChromeOSBrowse Google / ChromeOS | CVE List | 15753.50.0 to < 15753.50.0 | affected |
References
3issuetracker.google.com
https://issuetracker.google.com/issues/324336238 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-1122