VYPR
High severity8.8NVD Advisory· Published Apr 16, 2025· Updated Jun 17, 2026

CVE-2025-1568

CVE-2025-1568

Description

Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 16063.87.0 allows an attacker with a registered Gerrit account to inject malicious code into ChromeOS projects and potentially achieve Remote Code Execution and Denial of Service via editing trusted pipelines by insufficient access controls and misconfigurations in Gerrit's project.config.

Affected products

3
  • Google/ChromeOS2 versions
    cpe:2.3:o:google:chrome_os:16063.87.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:google:chrome_os:16063.87.0:*:*:*:*:*:*:*
    • (no CPE)range: 16063.87.0
  • Google/Chromecpe-rescue
    Range: 16063.87.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.