Vulnerability Description
DNS Leak in Native System VPN in Google ChromeOS Dev Channel on ChromeOS 16002.23.0 allows network observers to expose plaintext DNS queries via failure to properly tunnel DNS traffic during VPN state transitions.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chrome Os | 16002.23.0 |
Related Weaknesses (CWE)
References
- https://issues.chromium.org/issues/b/342802975Broken Link
- https://issuetracker.google.com/issues/342802975Issue TrackingMailing List
FAQ
What is CVE-2025-1566?
CVE-2025-1566 is a vulnerability with a CVSS score of 7.5 (HIGH). DNS Leak in Native System VPN in Google ChromeOS Dev Channel on ChromeOS 16002.23.0 allows network observers to expose plaintext DNS queries via failure to properly tunnel DNS traffic during VPN state...
How severe is CVE-2025-1566?
CVE-2025-1566 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-1566?
Check the references section above for vendor advisories and patch information. Affected products include: Google Chrome Os.