New Sh1mmer Exploit Allows Root Level Access for ChromeOS

A new exploit, dubbed SH1MMER, has been devised to unenroll enterprise- or school-managed Chromebooks from administrative control, letting a user bypass admin restrictions. The exploit uses publicly leaked Return Merchandise Authorization (RMA) shims to modify the management of enrollment of devices. Google is working with hardware partners to address it.


>>More