CVE-2025-1292

Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain persistence and bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:google:chrome:122.0.6261.132:*:*:*:*:*:*:*
cpe:2.3:o:google:chrome_os:-:*:*:*:*:*:*:*

History

06 Oct 2025, 16:55

Type Values Removed Values Added
CPE cpe:2.3:o:google:chrome_os:-:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:122.0.6261.132:*:*:*:*:*:*:*
First Time Google
Google chrome Os
Google chrome
References () https://issues.chromium.org/issues/b/324336238 - () https://issues.chromium.org/issues/b/324336238 - Broken Link
References () https://issuetracker.google.com/issues/324336238 - () https://issuetracker.google.com/issues/324336238 - Exploit, Issue Tracking

17 Apr 2025, 20:15

Type Values Removed Values Added
CWE CWE-787
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.7

16 Apr 2025, 13:25

Type Values Removed Values Added
Summary
  • (es) La escritura fuera de los límites en TPM2 Reference Library in Google ChromeOS 122.0.6261.132 estable en placas Cr50 permite que un atacante con acceso de root obtenga persistencia y eluda la verificación del sistema operativo mediante la explotación de la funcionalidad NV_Read durante el proceso de desafío-respuesta.

15 Apr 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-15 20:15

Updated : 2025-10-06 16:55


NVD link : CVE-2025-1292

Mitre link : CVE-2025-1292

CVE.ORG link : CVE-2025-1292


JSON object : View

Products Affected

google

  • chrome
  • chrome_os
CWE
CWE-787

Out-of-bounds Write