Permissions Bypass in Google ChromeOS Extensions Management
CVE-2025-6179

9.8CRITICAL

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
16 June 2025

What is CVE-2025-6179?

A permissions bypass vulnerability in the extension management of Google ChromeOS version 16181.27.0 enables local attackers to disable security extensions. This flaw grants unauthorized access to Developer Mode, allowing malicious users to load additional extensions using tools such as ExtHang3r and ExtPrint3r. The exploitation of this vulnerability poses serious risks, as it can lead to unauthorized remote code execution and further compromise of managed Chrome devices.

Affected Version(s)

ChromeOS 16181.27.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-6179 : Permissions Bypass in Google ChromeOS Extensions Management