Security features bypass in Chrome OS - #VU77120
Published: June 9, 2023
Vulnerability identifier: #VU77120
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-254
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows an attacker to bypass implemented security restrictions.
The vulnerability exists due to an unspecified error. An attacker can execute unsigned code on enrolled devices via a modified RMA shim.
Affected software
Chrome OS
Remediation
Install updates from vendor's website.
Chrome OS - update to 114.0.5735.119