CVE-2025-1121: Google Chrome OS

Medium severity, CVSS 6.8. EPSS: 0.1% chance of exploitation in the next 30 days.

Privilege escalation in Installer and Recovery image handling in Google ChromeOS version 15786.48.2 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image.

Affected products

  • Google Chrome OS: version 15786.48.0 only

Published 2025-03-07. Last modified 2026-06-17.