CVE-2025-1568 – Google ChromeOS Gerrit Access Control Code Injection Vulnerability

The following table lists the changes that have been made to the
CVE-2025-1568 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by 7f6e188d-c52a-4a19-8674-3c3fa7d1fc7f

    Apr. 16, 2025

    Action Type Old Value New Value
    Added Description Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 131.0.6778.268 allows an attacker with a registered Gerrit account to inject malicious code into ChromeOS projects and potentially achieve Remote Code Execution and Denial of Service via editing trusted pipelines by insufficient access controls and misconfigurations in Gerrit’s project.config.
    Added Reference https://issues.chromium.org/issues/b/374279912
    Added Reference https://issuetracker.google.com/issues/374279912
Share the Post:

Related Posts