ChromeOS Project
First CVE: Mar 7, 2025Active for: 1 year
12
CVEs Published
More CVEs Published than 30% of tracked CNAs
12.0
Avg CVEs / Year
More Avg CVEs / Year than 58% of tracked CNAs
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by ChromeOS Project over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 7, 2025
16 months ago
Most Recent CVE
Jul 7, 2025
382 days ago
Top CVEs
All CVEs published by ChromeOS Project as a CNA, regardless of affected vendor or product.
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-6179CRITICAL Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed Chrome devices allows a local attacker to disable extensions and access Developer Mode, | Jun 16, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-1568HIGH Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 16063.87.0 allows an attacker with a registered Gerrit account to inject malicious code i | Apr 16, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-2073HIGH Out-of-Bounds Read in netfilter/ipset in Linux Kernel ChromeOS [6.1, 5.15, 5.10, 5.4, 4.19] allows a local attacker with low privileges to trigger an out-of-bounds read, potentiall | Apr 16, 2025 | 8.8 | 25 | NO | NO |
CVE-2025-1290HIGH A race condition Use-After-Free vulnerability exists in the virtio_transport_space_update function within the Kernel 5.4 on ChromeOS. Concurrent allocation and freeing of the virti | Apr 17, 2025 | 8.1 | 24 | NO | NO |
CVE-2025-1566HIGH DNS Leak in Native System VPN in Google ChromeOS Dev Channel on ChromeOS 16002.23.0 allows network observers to expose plaintext DNS queries via failure to properly tunnel DNS traf | Apr 16, 2025 | 7.5 | 22 | NO | NO |
CVE-2025-6177HIGH Privilege Escalation in MiniOS in Google ChromeOS (16063.45.2 and potentially others) on enrolled devices allows a local attacker to gain root code execution via exploiting a debug | Jun 16, 2025 | 7.4 | 21 | NO | NO |
CVE-2025-2509HIGH Out-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address access within the crosvm sandboxed process, potentially leading | May 6, 2025 | 7.8 | 21 | NO | NO |
CVE-2025-6044MEDIUM An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the garaged stylus devices allows a physical attacker to bypass the | Jul 7, 2025 | 6.1 | 20 | NO | NO |
CVE-2025-1704MEDIUM ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users with local access to unenroll devices
and intercept device | Apr 16, 2025 | 6.5 | 20 | NO | NO |
CVE-2025-1292MEDIUM Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain persistence and
bypass operating | Apr 15, 2025 | 6.7 | 20 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA12 CVEs
42%
50%
8%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (33.3%)
Network6 (50.0%)
Unknown0 (0.0%)
Physical2 (16.7%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (83.3%)
High2 (16.7%)
Unknown0 (0.0%)
User Interaction
None12 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (33.3%)
High2 (16.7%)
None6 (50.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by ChromeOS Project as a CNA.
Media Mentions
Media articles that mention a CVE ID published by ChromeOS Project as a CNA — matched by CVE ID, not by organization name.