New issue
Advanced search Search tips

Issue 594855 link

Starred by 0 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Mar 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Bypass enterprise enrollment on Chromebook

Reported by cslobod...@icsd.k12.ny.us, Mar 15 2016

Issue description

VULNERABILITY DETAILS


VERSION
Chrome Version: verified in 39-47, have not yet tested in 48 and 49
Operating System: Chrome OS

REPRODUCTION CASE
Chromebooks that I have tested, HP, Asus and Dell can all get around the forced reenrollment by simply unplugging the battery, then plugging into AC power. This then allows the user to bypass all forced domain policies. 

 
Cc: rickyz@chromium.org
Status: WontFix (was: Unconfirmed)
This should not be possible. Please test with a latest version of Chrome Stable.
Just got a Chromebook up to version 49. Tested with same procedure, unplugged the battery, plugged into AC power and was able to get the Chromebook into developer mode successfully.
This is still reproducible with current OS
Project Member

Comment 4 by sheriffbot@chromium.org, Jun 21 2016

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 5 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 6 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment