CVE-2025-1122: Google Chrome
Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.
Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker with root access to gain persistence and Bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process.
Affected products
- Google Chrome: version 122.0.6261.132 only
Published 2025-04-15. Last modified 2026-06-17.