{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2025-1704","assignerOrgId":"7f6e188d-c52a-4a19-8674-3c3fa7d1fc7f","state":"PUBLISHED","assignerShortName":"ChromeOS","dateReserved":"2025-02-25T23:19:38.958Z","datePublished":"2025-04-16T23:06:28.279Z","dateUpdated":"2025-05-08T19:15:06.471Z"},"containers":{"cna":{"affected":[{"vendor":"Google","product":"ChromeOS","versions":[{"version":"15823.23.0","status":"affected","lessThan":"15823.23.0","versionType":"custom"}]}],"descriptions":[{"lang":"en","value":"ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users with local access to unenroll devices \nand intercept device management requests via loading components from the unencrypted stateful partition."}],"problemTypes":[{"descriptions":[{"lang":"en","description":"Use-After-Free (UAF)"}]}],"providerMetadata":{"orgId":"7f6e188d-c52a-4a19-8674-3c3fa7d1fc7f","shortName":"ChromeOS","dateUpdated":"2025-05-08T19:15:06.471Z"},"references":[{"url":"https://issuetracker.google.com/issues/359915523"},{"url":"https://issues.chromium.org/issues/b/359915523"}]},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-416","lang":"en","description":"CWE-416 Use After Free"}]}],"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":6.5,"attackVector":"NETWORK","baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"LOW","confidentialityImpact":"NONE"}},{"other":{"type":"ssvc","content":{"timestamp":"2025-04-17T15:48:23.843965Z","id":"CVE-2025-1704","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-05-07T19:45:03.703Z"}}]}}