CVE-2025-1568: Google Chrome OS
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 16063.87.0 allows an attacker with a registered Gerrit account to inject malicious code into ChromeOS projects and potentially achieve Remote Code Execution and Denial of Service via editing trusted pipelines by insufficient access controls and misconfigurations in Gerrit's project.config.
Affected products
- Google Chrome OS: version 16063.87.0 only
Published 2025-04-16. Last modified 2026-06-17.