CVE-2025-6179: Google Chrome OS

Critical severity, CVSS 9.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed Chrome devices allows a local attacker to disable extensions and access Developer Mode, including loading additional extensions via exploiting vulnerabilities using the ExtHang3r and ExtPrint3r tools.

Affected products

  • Google Chrome OS: version 16181.27.0 only

Published 2025-06-16. Last modified 2026-06-17.