Google Looker security bulletin fix (multiple vulnerabilities)
Security Patch Release
Summary
Hide ▲
Show ▼
Google issued a security fix for Looker in GCP-2025-052 after Tenable Research disclosed LeakyLooker findings, a set of nine cross-tenant vulnerabilities in Looker Studio that could let attackers extract or manipulate sensitive cloud data. The flaws included 0-click attacks against report-owner credentials and 1-click attacks against viewer credentials, with potential impact across BigQuery, Spanner, PostgreSQL, MySQL, Google Sheets, and Cloud Storage. Because Looker Studio is a managed service, Google deployed the patches globally, and no customer action required for that product; on-premises Looker customers must still update to a secure version from the bulletin.
Related Happenings
Google Gemini CLI workspace-trust hardening update
Security Patch Release
H score44
First: 30.04.2026 10:07
Last: 30.04.2026 10:07
Sources 1
About this happening:
Google released a Gemini CLI security update that changes workspace-trust handling for headless CI workflows, reducing the risk that untrusted folders can trigger ho...
Google Gemini CLI workspace-trust hardening update
Security Patch ReleaseAbout this happening: Google released a Gemini CLI security update that changes workspace-trust handling for headless CI workflows, reducing the risk that untrusted folders can trigger ho...
Google Antigravity prompt-injection fix
Security Patch Release
H score31
First: 21.04.2026 13:52
Last: 21.04.2026 13:52
Sources 1
About this happening:
Google fixed Antigravity's prompt injection flaw in February, closing a path that could lead to sandbox escape and remote code execution (RCE). The patch f...
Google Antigravity prompt-injection fix
Security Patch ReleaseAbout this happening: Google fixed Antigravity's prompt injection flaw in February, closing a path that could lead to sandbox escape and remote code execution (RCE). The patch f...
Chrome emergency zero-day patch (CVE-2026-3909, CVE-2026-3910)
Security Patch Release
H score41
First: 13.03.2026 08:56
Last: 13.03.2026 08:56
Sources 1
About this happening:
Google pushed an emergency Chrome update for Stable Desktop users on Windows, macOS, and Linux after confirming CVE-2026-3909 and CVE-2026-3910 are explo...
Chrome emergency zero-day patch (CVE-2026-3909, CVE-2026-3910)
Security Patch ReleaseAbout this happening: Google pushed an emergency Chrome update for Stable Desktop users on Windows, macOS, and Linux after confirming CVE-2026-3909 and CVE-2026-3910 are explo...
Latest development: 13.03.2026 11:17
Google discovers and reports CVE-2026-3909, an out-of-bounds write vulnerability in the Skia 2D graphics library, and CVE-2026-3910, an inappropriate implementation vulnerability in the V8 JavaScript and WebAssembly engine, on March 10, 2026; both issues are reachable via crafted HTML pages.
Google Cloud environment entry vectors shift from credentials to third-party vulnerabilities in H2 2025
Trend
H score38
First: 10.03.2026 17:30
Last: 10.03.2026 17:30
Sources 1
About this happening:
Threat actors targeting Google Cloud environments shifted in H2 2025 from credential abuse to unpatched third-party vulnerabilities, materially changing initial-access...
Google Cloud environment entry vectors shift from credentials to third-party vulnerabilities in H2 2025
TrendAbout this happening: Threat actors targeting Google Cloud environments shifted in H2 2025 from credential abuse to unpatched third-party vulnerabilities, materially changing initial-access...
Cloud environments third-party flaw exploitation wave
Exploitation Wave
H score37
First: 09.03.2026 23:45
Last: 09.03.2026 23:45
Sources 1
About this happening:
Threat actors are rapidly weaponizing newly disclosed third-party vulnerabilities to reach cloud environments, compressing the exploitation window from weeks to days a...
Cloud environments third-party flaw exploitation wave
Exploitation WaveAbout this happening: Threat actors are rapidly weaponizing newly disclosed third-party vulnerabilities to reach cloud environments, compressing the exploitation window from weeks to days a...
Timeline
-
04.02.2026 13:00 3 articles · 5mo ago
Tenable discloses Looker SQL injection and RCE flaws
Initial DisclosureTenable researcher Liv Matan disclosed two Looker flaws: a SQL injection path that could expose the internal database's secrets and configurations as CVE-2025-12743, and a chained RCE path that could run arbitrary code on a Looker server and enable lateral movement or cross-tenant access in cloud deployments. Google later fixed the issues and published secure versions in GCP-2025-052 for on-premises customers.
Show sources
- Google Looker Bugs Allow Cross-Tenant RCE, Data Exfil — www.darkreading.com — 04.02.2026 13:00
- Google Looker Bugs Allow Cross-Tenant RCE, Data Exfil — www.darkreading.com — 04.02.2026 13:00
- Researchers Uncover ‘LeakyLooker’ Vulnerabilities in Google Looker Studio — www.infosecurity-magazine.com — 11.03.2026 18:00