Google Fixed Cloud Run Vulnerability Allowing Unauthorized Image Access via IAM Misuse

Google recently patched a critical vulnerability in its Cloud Run service, called "ImageRunner," which could have allowed attackers to access private container images and inject malicious code. The flaw, discovered by Tenable, exploited permissions in Cloud Run revisions to bypass security measures, potentially leading to data theft or espionage. Google addressed the issue in January 2025 by requiring explicit permissions for accessing container images, ensuring enhanced security for its users.