Cyber Security
Tenable Uncovers “GerriScary” Supply‑Chain Compromise Vulnerability In Popular Google’s Open‑Source Projects
By Nikhil Sonawane

Updated on Wed, Jun 18, 2025
New Delhi, June 18, 2025 - Tenable, the exposure management company, has identified a vulnerability in Google’s open-source code review system, Gerrit, dubbed GerriScary. The vulnerability allowed unauthorised code submission to at least 18 major Google projects, including ChromiumOS (CVE-2025-1568), Chromium, Dart, and Bazel. GerriScary could have allowed attackers to submit unauthorised code revisions to existing change requests, bypassing manual approvals and enabling malicious code injection into major projects.
Tenable researchers discovered that misconfigured permissions in Gerrit, specifically the “addPatchSet” setting, combined with the way code tickets submit requirements were inherited between revisions, created an exploitable condition. As a result, attackers could exploit automated merging bots to deploy unreviewed malicious code with no user interaction, effectively creating a zero-click supply chain compromise.
GerriScary is a stark reminder of the cascading risks inherent in open-source ecosystems and automated developer workflows, where configuration weaknesses and automation can inadvertently widen the attack surface. "In software development, trust is paramount, especially in open-source collaboration platforms like Gerrit," said Liv Matan, Senior Security Researcher at Tenable. "GerriScary exposed a critical pathway for attackers to bypass established security protocols and directly compromise the integrity of core software projects. This serves as a stark reminder that even the most robust ecosystems must meticulously scrutinise every link in their supply chain."
Potential Impact of GerriScary Exploitation
If exploited, GerriScary could have allowed attackers to:
-
Inject malicious code into widely used at least 18 Google projects such as Chromium, Bazel, and Dart
-
Bypass human review through label inheritance and automation
-
Tamper with code in software relied on by millions globally
Recommendations for Security Teams
While the specific flaw has been addressed by Google, Tenable recommends organisations using Gerrit:
-
Audit permissions, especially the “addPatchSet” setting default
-
Disable or restrict label copying across patch sets
-
Review automation workflows to mitigate race conditions in approvals
“GerriScary underscores why proactive security is non-negotiable. As environments spiral in complexity, security teams simply must anticipate and mitigate risks before attackers even have a chance to exploit them,” added Matan.
Read the full research findings here:
https://www.tenable.com/blog/gerriscary-hacking-the-supply-chain-of-popular-google-products-chromiumos-chromium-bazel-dart
About Tenable
Tenable® is the exposure management company, exposing and closing the cybersecurity gaps that erode business value, reputation and trust. The company’s AI-powered exposure management platform radically unifies security visibility, insight and action across the attack surface, equipping modern organizations to protect against attacks from IT infrastructure to cloud environments to critical infrastructure and everywhere in between. By protecting enterprises from security exposure, Tenable reduces business risk for approximately 44,000 customers around the globe. Learn more at tenable.com.
Media Contact:
Adarsh Ram
+91 9741470477
adarsh@starsquaredpr.com
First published on Wed, Jun 18, 2025
Liked what you read? That’s only the tip of the tech iceberg!
Explore our vast collection of tech articles including introductory guides, product reviews, trends and more, stay up to date with the latest news, relish thought-provoking interviews and the hottest AI blogs, and tickle your funny bone with hilarious tech memes!
Plus, get access to branded insights from industry-leading global brands through informative white papers, engaging case studies, in-depth reports, enlightening videos and exciting events and webinars.
Dive into TechDogs' treasure trove today and Know Your World of technology like never before!
Disclaimer - Reference to any specific product, software or entity does not constitute an endorsement or recommendation by TechDogs nor should any data or content published be relied upon. The views expressed by TechDogs' members and guests are their own and their appearance on our site does not imply an endorsement of them or any entity they represent. Views and opinions expressed by TechDogs' Authors are those of the Authors and do not necessarily reflect the view of TechDogs or any of its officials. While we aim to provide valuable and helpful information, some content on TechDogs' site may not have been thoroughly reviewed for every detail or aspect. We encourage users to verify any information independently where necessary.
Trending TD NewsDesk
FBI & Security Firms Warn Cybergang Scattered Spider Moving Focus To Airlines
By TechDogs Bureau
AI In Healthcare: Ant Group’s App, Funding Rounds, Growing Use Cases And Woes
By TechDogs Bureau
Google-Pearson, Microsoft-OpenStax & Other Alliances Propel EdTech's AI Phase
By TechDogs Bureau
Meta Adds Features To Instagram And WhatsApp While "Poaching" OpenAI's Talent
By TechDogs Bureau
Tesla’s Texas Tests Tainted By Mistakes As Waymo-Uber Robotaxis Enter Atlanta
By TechDogs Bureau
Join Our Newsletter
Get weekly news, engaging articles, and career tips-all free!
By subscribing to our newsletter, you're cool with our terms and conditions and agree to our Privacy Policy.
Join The Discussion