Security researchers from Tenable have discovered a vulnerability called GerriScary in Google's open source code review system Gerrit. The vulnerability allowed malicious code to be injected into at least 18 central Google projects, including ChromiumOS (CVE-2025-1568), Chromium, Dart and Bazel. Attackers could have used GerriScary to manipulate existing change requests, bypass release mechanisms and inject malicious code into critical projects.
Translate
Blogs
Links
Social networks
Awards
Sponsors
(Paypal-Donations)
[
[
[

