Privilege Escalation Vulnerability in MiniOS on Google ChromeOS
CVE-2025-6177
Currently unrated
What is CVE-2025-6177?
This vulnerability in MiniOS found in Google ChromeOS, specifically affecting version 16063.45.2 and potentially earlier versions, allows local attackers to gain root code execution. By exploiting a debug shell accessible via specific key combinations while in developer mode – even if this mode is intended to be blocked – an attacker may circumvent security measures like device policy settings and Firmware Write Protect (FWMP). This poses significant risks for enrolled devices.
Affected Version(s)
ChromeOS 16063.45.2