Security features bypass in Chrome OS - #VU77120

 

Security features bypass in Chrome OS - #VU77120

Published: June 9, 2023


Vulnerability identifier: #VU77120
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-254
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to bypass implemented security restrictions.

The vulnerability exists due to an unspecified error. An attacker can execute unsigned code on enrolled devices via a modified RMA shim.


Affected software

Chrome OS

Remediation

Install updates from vendor's website.

Chrome OS - update to 114.0.5735.119

External References

Related Security Bulletins