Bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process.
Metrics
Affected Vendors & Products
Source | ID | Title |
---|---|---|
![]() |
EUVD-2025-10991 | Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker with root access to gain persistence and Bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 06 Oct 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Google
Google chrome Google chrome Os |
|
CPEs | cpe:2.3:a:google:chrome:122.0.6261.132:*:*:*:*:*:*:* cpe:2.3:o:google:chrome_os:-:*:*:*:*:*:*:* |
|
Vendors & Products |
Google
Google chrome Google chrome Os |
Tue, 06 May 2025 01:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain persistence and Bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process. | Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker with root access to gain persistence and Bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process. |
Thu, 17 Apr 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-787 | |
Metrics |
cvssV3_1
|
Thu, 17 Apr 2025 00:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain persistence and bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process. | Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain persistence and Bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process. |
Wed, 16 Apr 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | TPM2 Out-Of-Bounds Write Leading to Potential Operating System Verification Bypass in ChromeOS |
Tue, 15 Apr 2025 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain persistence and bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process. | |
Title | TPM2 Out-Of-Bounds Write Leading to Potential Operating System Verification Bypass in ChromeOS | |
References |
|

Status: PUBLISHED
Assigner: ChromeOS
Published:
Updated: 2025-05-08T19:15:05.948Z
Reserved: 2025-02-07T18:38:22.520Z
Link: CVE-2025-1122

Updated: 2025-04-15T20:43:15.358Z

Status : Analyzed
Published: 2025-04-15T20:15:38.317
Modified: 2025-10-06T16:56:59.303
Link: CVE-2025-1122

No data.

No data.