CVE-2025-1566
Google Chrome Os 16002.23.0
Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HSummary
CVE-2025-1566 is a high-severity EM-FI (CWE-1319) vulnerability in Google Chrome Os. Its CVSS base score is 7.5 (High).
Operationally, ranked at the 9th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to SA-18 (Tamper Resistance and Detection) and SR-9 (Tamper Resistance and Detection) — see the control section below for these in your framework.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-11529
Vulnerability Data
DNS Leak in Native System VPN in Google ChromeOS Dev Channel on ChromeOS 16002.23.0 allows network observers to expose plaintext DNS queries via failure to properly tunnel DNS traffic during VPN state transitions.
- CWE(s)
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Tamper-resistance requirements directly drive hardware protections that block EM fault injection from reaching internal state or bypassing checks.
Mandating a tamper-protection program for components forces implementation of EM-FI countermeasures during development and supply-chain handling.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Managing physical access directly reduces the opportunity to perform EM-FI attacks.
Physical-environment monitoring can detect EM-FI attempts or related tampering.
Protecting assets from environmental threats encompasses electromagnetic fault-injection vectors.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing in development can discover EM-FI susceptibility, but does not inherently prevent the weakness in production.
Physical and environmental threat protection directly addresses EM-FI risk through shielding and environmental controls.
Equipment siting and protection can reduce exposure to EM sources but does not specifically target fault-injection vectors.
Secure system architecture principles can include hardware-level countermeasures against EM-FI, though the control is not specific to this threat.