Google Cloud Platform Vulnerability Exposes Sensitive Data to Attackers
ID: 395b216e-d28c-5e7d-a778-133fcdcd7b18
STIX ID: report--395b216e-d28c-5e7d-a778-133fcdcd7b18
Feed Name: GBHackers
Threat Score
A GCP Cloud Run privilege-escalation flaw called "ImageRunner" allowed identities with run.services.update and iam.serviceAccounts.actAs to modify service revisions and point them at private container images—bypassing registry read permissions and risking exposure of proprietary code and secrets; Tenable Research disclosed the issue and Google implemented a mandatory fix on January 28, 2025 requiring explicit image read permissions to mitigate the risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
