Google 'ImageRunner' Bug Enabled Privilege Escalation
ID: 3469732f-d961-5ade-833c-2a99e949eb51
STIX ID: report--3469732f-d961-5ade-833c-2a99e949eb51
Feed Name: Dark Reading
Date Published: 2025-04-01
Date Updated: 2026-04-21
Author: Alexander Culafi, Senior News Writer, Dark Reading
ImageRunner: A GCP Cloud Run privilege-escalation vulnerability allowed identities with run.services.update and iam.serviceAccounts.actAs (but lacking registry read roles) to cause Cloud Run service agents to pull private container images and execute injected commands, potentially exposing image contents and secrets; Google implemented an IAM check to require explicit image read permission and fully deployed the fix on 2025-01-28.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
