Permissions Bypass in Google ChromeOS Extensions Management
CVE-2025-6179
Currently unrated
What is CVE-2025-6179?
A permissions bypass vulnerability in the extension management of Google ChromeOS version 16181.27.0 enables local attackers to disable security extensions. This flaw grants unauthorized access to Developer Mode, allowing malicious users to load additional extensions using tools such as ExtHang3r and ExtPrint3r. The exploitation of this vulnerability poses serious risks, as it can lead to unauthorized remote code execution and further compromise of managed Chrome devices.
Affected Version(s)
ChromeOS 16181.27.0