logo

Google 'ImageRunner' Bug Enabled Privilege Escalation

ID: 3469732f-d961-5ade-833c-2a99e949eb51

STIX ID: report--3469732f-d961-5ade-833c-2a99e949eb51

Feed Name: Dark Reading

Threat Score
60/100

Date Published: 2025-04-01

Date Updated: 2026-04-21

Author: Alexander Culafi, Senior News Writer, Dark Reading

...
...

ImageRunner: A GCP Cloud Run privilege-escalation vulnerability allowed identities with run.services.update and iam.serviceAccounts.actAs (but lacking registry read roles) to cause Cloud Run service agents to pull private container images and execute injected commands, potentially exposing image contents and secrets; Google implemented an IAM check to require explicit image read permission and fully deployed the fix on 2025-01-28.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.