CVE-2025-6044
CVE-2025-6044 is a medium-severity vulnerability in Google Chrome Os with a CVSS 3.x base score of 6.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-287.
Key facts
- Severity: Medium (CVSS 3.x base score 6.1)
- EPSS exploit prediction: 0% (2nd percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-20310
- Weakness: CWE-287
- Affected product: Google Chrome Os
- Published:
- Last modified:
Description
An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the garaged stylus devices allows a physical attacker to bypass the lock screen and access user files by removing the stylus while the device is closed and using the screen capture feature.
Frequently asked questions
- What is CVE-2025-6044?
- An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the garaged stylus devices allows a physical attacker to bypass the lock screen and access user files by removing the stylus while the device is closed and using the screen capture feature.
- How severe is CVE-2025-6044?
- CVE-2025-6044 has a CVSS 3.x base score of 6.1, rated medium severity. It is exploitable over physical access with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability none.
- Is CVE-2025-6044 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (2nd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2025-6044?
- CVE-2025-6044 affects Google Chrome Os. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2025-6044?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2025-6044 have an EU (EUVD) identifier?
- Yes. CVE-2025-6044 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-20310.
- When was CVE-2025-6044 published?
- CVE-2025-6044 was published on 2025-07-07 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:o:google:chrome_os:16238.64.0:*:*:*:*:*:*:*
More vulnerabilities in Google Chrome Os
- CVE-2014-3188 — Critical (CVSS 10.0): Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 do not properly handle the interaction of IPC and…
- CVE-2014-1708 — Critical (CVSS 10.0): The boot implementation in Google Chrome OS before 33.0.1750.152 does not properly consider file persistence, which…
- CVE-2013-2833 — Critical (CVSS 10.0): Use-after-free vulnerability in the O3D plug-in in Google Chrome OS before 26.0.1410.57 allows remote attackers to…
- CVE-2013-0915 — Critical (CVSS 10.0): The GPU process in Google Chrome OS before 25.0.1364.173 allows attackers to cause a denial of service or possibly have…
- CVE-2012-2864 — Critical (CVSS 10.0): Mesa, as used in Google Chrome before 21.0.1183.0 on the Acer AC700, Cr-48, and Samsung Series 5 and 5 550 Chromebook…
- CVE-2012-4050 — Critical (CVSS 10.0): Multiple unspecified vulnerabilities in Google Chrome OS before 21.0.1180.50 on the Cr-48 and Samsung Series 5 and 5…
All CVEs affecting Google Chrome Os →
Other CWE-287 (Improper Authentication) vulnerabilities
- CVE-2026-101077 — Critical (CVSS 10.0): A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp…
- CVE-2026-100886 — Critical (CVSS 10.0): A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected…
- CVE-2026-77244 — Critical (CVSS 10.0): MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0,…
- CVE-2026-94493 — Critical (CVSS 10.0): A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of…
- CVE-2026-83099 — Critical (CVSS 10.0): Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).…
- CVE-2026-83059 — Critical (CVSS 10.0): Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server).…
Browse all CWE-287 (Improper Authentication) vulnerabilities →