cvedb.io
CVE-2025-1568
HIGH · CVSS 8.8
EPSS exploitation probability: 0%
Published 2025-04-16T23:15:44.853 · Last modified 2026-06-17T08:39:22.873

Summary

Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 16063.87.0 allows an attacker with a registered Gerrit account to inject malicious code into ChromeOS projects and potentially achieve Remote Code Execution and Denial of Service via editing trusted pipelines by insufficient access controls and misconfigurations in Gerrit's project.config.

Affected products

google — chrome_os

Does this affect you?

Add your gear to cvedb and we'll alert you only when google ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.