{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2025-1566","assignerOrgId":"7f6e188d-c52a-4a19-8674-3c3fa7d1fc7f","state":"PUBLISHED","assignerShortName":"ChromeOS","dateReserved":"2025-02-21T21:30:53.937Z","datePublished":"2025-04-16T23:06:27.847Z","dateUpdated":"2025-05-08T19:15:06.169Z"},"containers":{"cna":{"affected":[{"vendor":"Google","product":"ChromeOS","versions":[{"version":"16002.23.0","status":"affected","lessThan":"16002.23.0","versionType":"custom"}]}],"descriptions":[{"lang":"en","value":"DNS Leak in Native System VPN in Google ChromeOS Dev Channel on ChromeOS 16002.23.0 allows network observers to expose plaintext DNS queries via failure to properly tunnel DNS traffic during VPN state transitions."}],"problemTypes":[{"descriptions":[{"lang":"en","description":"Network Security Isolation (NSI)"}]}],"providerMetadata":{"orgId":"7f6e188d-c52a-4a19-8674-3c3fa7d1fc7f","shortName":"ChromeOS","dateUpdated":"2025-05-08T19:15:06.169Z"},"references":[{"url":"https://issuetracker.google.com/issues/342802975"},{"url":"https://issues.chromium.org/issues/b/342802975"}]},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-1319","lang":"en","description":"CWE-1319 Improper Protection against Electromagnetic Fault Injection (EM-FI)"}]}],"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":7.5,"attackVector":"NETWORK","baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"NONE","confidentialityImpact":"NONE"}},{"other":{"type":"ssvc","content":{"timestamp":"2025-04-17T13:32:48.693962Z","id":"CVE-2025-1566","options":[{"Exploitation":"poc"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-05-07T19:45:29.043Z"}}]}}