According to
The Chromium Projects, an attacker who has access to the public central could take advantage of a flaw in the Trusted Platform Module (TPM) firmware on many Chromebook models. The assaulter could exploit this flaw to gain access to the private key created by the TPM.

Fortunately a fix for the flaw exists, but it requires that you erase all information from your Chromebook and sign in every bit a new user. The process doesn’t crave more than a few minutes. However the more devices you need to update, the greater the full time required.

Organizations will likely want to prioritize firmware updates on Chromebooks used by people with access to sensitive information. For example, people who piece of work in healthcare or who carry a Chromebook beyond international borders should update equally shortly as possible.

Here’due south how to check your Chromebook firmware version and how to update your device without losing whatsoever data.

Read:  S7 Edge G935p Sboot Combination Firmware Z3x

1. Bank check Chrome Bone firmware version

Open a new browser window on your Chrome device and enter chrome://arrangement, then press enter. Await a chip for the folio to fill with the details of your system. Scroll downwards the page toward the end until you run into tpm_version forth the left. Select “Expand…” to run across your device’s TPM firmware version.

According to the page posted at Chromium.org, the following Chrome Bone TPM versions are vulnerable:

  • 000000000000041f
  • 0000000000000420
  • 0000000000000628
  • 0000000000008520

2. Save settings and files

Review the sync settings for your account. If y’all sync everything, your apps, bookmarks, extensions, history, passwords, settings, themes, and more will exist restored when you re-sync the Chromebook after the update. To adjust the settings, open up a new browser window on your Chrome device, and so enter chrome://system/syncSetup. Adjust settings equally desired. Look a few minutes after you lot make changes to give the arrangement time to save data.

Brand a re-create of any files stored on the device that you desire to save. All files on the device will exist deleted as function of the update process. I detect it simplest to drag-and-drop locally stored files from the device (e.chiliad., the “Downloads” binder) to Google Bulldoze. If you take many files, you may want to create a new folder for these items.

3. Create Chrome recovery media

While technically optional, I recommend you create recovery media for your device. Install the Chromebook Recovery Utility app, then run it. The app identifies your device, downloads a recovery prototype, formats the USB or SD card you’ve selected, and stores the recovery paradigm for the selected device. Should your update fail for whatever reason, you tin can use this USB device or SD card to restore your Chromebook to a working state. Annotation that you don’t demand to brand a recovery image for every device. Instead, I advise you lot create recovery media for each unlike Chrome Bone model. For instance, if you have 20 Samsung Chromebook 3 devices, I recommend that 1 recovery drive or card is sufficient.

Read:  Flash Verizon Samsung Galaxy S7 to T-mobile Samsung Galaxy S7 Firmware

4. Update with a Powerwash

Press Shift+Ctrl+Alt+r to initiate a factory reset (too called a Powerwash) on your Chrome device. You may exist prompted to restart your Chromebook. When prompted, be sure to bank check the box to “Update firmware for added security,” and then select “Powerwash.” Y’all may need to confirm that you lot want to erase the device. And so, await as the device resets and updates the firmware. You’ll meet a screen with a “Log in” option afterward the procedure completes. At that signal, connect to a network and sign in with your Google account.

To verify that the update completed, return to the chrome://system screen, scroll to the tpm_version data, expand it again, and you should see that the number has updated.

If people in your organisation employ Chromebooks, how has your organization decided to handle the TPM update? Have you lot already updated all devices? Or did y’all prioritize specific systems to receive the update over others? Let me know in the comments or on Twitter (@awolber).