CVE-2025-6179: Google Chrome OS
Critical severity, CVSS 9.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed Chrome devices allows a local attacker to disable extensions and access Developer Mode, including loading additional extensions via exploiting vulnerabilities using the ExtHang3r and ExtPrint3r tools.
Affected products
- Google Chrome OS: version 16181.27.0 only
Published 2025-06-16. Last modified 2026-06-17.