CVE-2025-6179
BaseFortify
Publication date: 2025-06-16
Last updated on: 2025-07-02
Assigner: ChromeOS
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| chrome_os | 16181.27.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-276 | During installation, installed file permissions are set to allow anyone to modify those files. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a permissions bypass in the Extension Management system of Google ChromeOS 16181.27.0 on managed Chrome devices. It allows a local attacker to disable extensions and access Developer Mode. The attacker can also load additional extensions by exploiting vulnerabilities using the ExtHang3r and ExtPrint3r tools.
How can this vulnerability impact me? :
This vulnerability can impact you by allowing a local attacker to disable security or functionality extensions and gain access to Developer Mode on managed Chrome devices. This could lead to unauthorized changes, loading of malicious extensions, and potential compromise of the device's security and integrity.