CVE-2025-6177 describes a privilege escalation vulnerability in MiniOS within Google ChromeOS (versions 16063.45.2 and potentially others) on enrolled devices. A local attacker can achieve root code execution by exploiting a debug shell accessible via specific key combinations during developer mode entry and MiniOS access, even when developer mode is policy-blocked or Firmware Write Protect (FWMP) is active. This vulnerability carries a CVSS score of 7.4 (HIGH), indicating high impact on confidentiality, integrity, and availability, with high attack complexity and no required privileges. Currently, there is no known public exploit code, active exploitation, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
16063.45.2CPE matchmatch criteria | cpe:2.3:o:google:chrome_os:16063.45.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.