CVE-2025-1704: Google Chrome OS

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users with local access to unenroll devices and intercept device management requests via loading components from the unencrypted stateful partition.

Affected products

  • Google Chrome OS: version 15823.23.0 only

Published 2025-04-16. Last modified 2026-06-17.