CVE-2025-6044

An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the garaged stylus devices allows a physical attacker to bypass the lock screen and access user files by removing the stylus while the device is closed and using the screen capture feature.
Configurations

No configuration.

History

09 Jul 2025, 19:15

Type Values Removed Values Added
Summary (en) An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on Lenovo devices allows a physical attacker to bypass the lock screen and access user files by removing the stylus while the device is closed and using the screen capture feature. (en) An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the garaged stylus devices allows a physical attacker to bypass the lock screen and access user files by removing the stylus while the device is closed and using the screen capture feature.

08 Jul 2025, 18:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CWE CWE-287

08 Jul 2025, 16:18

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de control de acceso inadecuado en el componente Stylus Tools de Google ChromeOS versión 16238.64.0 en dispositivos Lenovo permite a un atacante físico eludir la pantalla de bloqueo y acceder a los archivos del usuario quitando el lápiz mientras el dispositivo está cerrado y usando la función de captura de pantalla.

07 Jul 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-07 19:15

Updated : 2025-07-09 19:15


NVD link : CVE-2025-6044

Mitre link : CVE-2025-6044

CVE.ORG link : CVE-2025-6044


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication