CVE-2025-1122: TPM2 Out-Of-Bounds Write Leading to Potential Operating System Verification Bypass in ChromeOS

Description

Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain persistence and
bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process.

Classification

CVE ID: CVE-2025-1122

Problem Types

Out-of-bounds Write

Affected Products

Vendor: Google

Product: ChromeOS

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.01% (probability of being exploited)

EPSS Percentile: 0.28% (scored less or equal to compared to others)

EPSS Date: 2025-04-21 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-1122
https://issuetracker.google.com/issues/324336238
https://issues.chromium.org/issues/b/324336238

Timeline