logo

Google Looker Bugs Allow Cross-Tenant RCE, Data Exfil

ID: d74bba4a-cc9e-5b83-9c1d-9781f82de6a4

STIX ID: report--d74bba4a-cc9e-5b83-9c1d-9781f82de6a4

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-02-04

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Researchers disclosed two high-impact vulnerabilities in Google Looker: an error-based SQL injection that can leak the internal database (CVE-2025-12743) and a chained RCE that uses path traversal, Git hook manipulation, and a race condition to execute arbitrary code on Looker servers — potentially enabling lateral movement and cross-tenant access in GCP. Google patched the issues; organizations must apply updates, isolate Looker instances, and follow least-privilege practices to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.