logo

ConfusedFunction Flaw in Google Cloud Lets Hackers Escalate Privileges

ID: a6ddf524-406a-5c95-9409-50059ea76488

STIX ID: report--a6ddf524-406a-5c95-9409-50059ea76488

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2024-07-26

Date Updated: 2026-04-19

Author: Kaaviya

...
...

ConfusedFunction is a privilege-escalation vulnerability in Google Cloud Functions where a default Cloud Build service account with excessive permissions is attached to background Cloud Build instances during deployments; attackers can publish a malicious dependency (e.g., an npm package with a preinstall script) that executes in the build environment, retrieves the Cloud Build service account token from the metadata service, and exfiltrates it to impersonate the account and access GCP resources. Google introduced options to use a custom, limited service account and changed the default to the Compute Engine service account for new deployments, but existing Cloud Build service accounts may still retain excessive permissions and require remediation and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.