CVE-2025-1566: Google Chrome OS

High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.

DNS Leak in Native System VPN in Google ChromeOS Dev Channel on ChromeOS 16002.23.0 allows network observers to expose plaintext DNS queries via failure to properly tunnel DNS traffic during VPN state transitions.

Affected products

  • Google Chrome OS: version 16002.23.0 only

Published 2025-04-16. Last modified 2026-06-17.