This new Chromebook hack could let you sideload your work laptop


If you’re one of the more than 50 million Chromebook users in education (though Google (opens in new tab)’s figure is almost a year out of date), then you’ll be familiar with the restrictions imposed on your laptop to keep you within the realms of its intended use as a classroom tool.
Similar restrictions are also placed on company-provided business laptops to keep you from doing certain non-work-related tasks, leaving you with little choice but to invest in a secondary device to use as your own.
That is, until now. A new admin control exploit, called SH1MMER, uses legitimate tools approved by Google to break out of restricted mode. The hack, known in the industry as a shim, is ordinarily designed for laptop repairers to run diagnostics and fix devices.
Chromebook admin restrictions
A GitHub post (opens in new tab) explains how the shim works:
“RMA shims are a factory tool allowing certain authorization functions to be is signed, but only the KERNEL partitions are checked for signatures by the firmware. We can edit the other partitions to our will as long as we remove the forced readonly bit on them.”
Following a set of instructions posted on the SH1MMER website (opens in new tab), which includes loading a USB with at least 8GB of storage with a shim image, users will be able to unenroll their Chromebook seeing it “behave entirely as if it is a personal computer and no longer contain spyware or blocker extensions.”
Google is reportedly aware of the exploit that was found by the 15 members of the so-called Mercury Workshop, which was released on January 13, however several reports claim that it is still unpatched, including an education forum (opens in new tab).
The company says that Enterprise and Education administrators should continually monitor for inactive devices. They can also turn off enrollment permissions, block access to the Chromebook Recovery Utility extension, block access to chrome://net-export to prevent users from capturing wireless credentials, and block access to exploit-spreading website like sh1mmer.me, alicesworld.tech, luphoria.com, and bypassi.com/
TechRadar Pro is waiting to hear from Google whether it has issued a more permanent fix for this issue that could see many establishments in trouble.
Audio player loading… If you’re one of the more than 50 million Chromebook users in education (though Google (opens in new tab)’s figure is almost a year out of date), then you’ll be familiar with the restrictions imposed on your laptop to keep you within the realms of its intended…
Recent Posts
- With the Humane AI Pin now dead, what does the Rabbit R1 need to do to survive?
- One of the best AI video generators is now on the iPhone – here’s what you need to know about Pika’s new app
- Apple’s C1 chip could be a big deal for iPhones – here’s why
- Rabbit shows off the AI agent it should have launched with
- Instagram wants you to do more with DMs than just slide into someone else’s
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010