Google ChromeOS
cpe:2.3:o:google:chrome_os:*:*:*:*:*:*:*
- 16181.27.0
This vulnerability is being actively exploited in the wild.
A permissions bypass vulnerability has been identified in the extension management system of Google ChromeOS version 16181.27.0, specifically on managed Chrome devices. This vulnerability allows a local attacker to disable extensions and gain access to Developer Mode. Exploitation of this vulnerability can be achieved using the ExtHang3r and ExtPrint3r tools, available on GitHub. The issue has been reported to affect students in a school district, who are using it to bypass web filtering.
Exploitation of this vulnerability allows for the unauthorized disabling of extensions, access to Developer Mode, and the ability to load additional extensions on managed Chrome devices.
Google has implemented a short-term fix for this vulnerability and is working on a more robust, long-term solution, targeted for release in ChromeOS version M135.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.