DNS Leak Vulnerability in Google ChromeOS VPN
CVE-2025-1566

7.5HIGH

Key Information:

Vendor
Google
Status
Vendor
CVE Published:
16 April 2025

Summary

A DNS leak vulnerability has been identified in the Native System VPN of Google ChromeOS. This issue affects the transition of DNS traffic during VPN changes, potentially allowing network observers to intercept plaintext DNS queries. Users may unknowingly expose their browsing activity, leading to privacy concerns. This vulnerability highlights the need for securing DNS traffic in VPN environments to maintain user confidentiality.

Affected Version(s)

ChromeOS 129.0.6668.36

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.