// Alert

Google Cloud threat report

CVE-2025-0982: Sandbox escape vulnerability in Google Cloud Application Integration allows arbitrary command execution within Google's Borg infrastructure. Vulnerability enabled complete escape from the Rhino JavaScript execution environment and execution of arbitrary commands on internal production systems. Google mitigated the issue within 48 hours of disclosure (Mar 30, 2026), deprecated Rhino entirely, and migrated JavaScript tasks to the V8 engine. Security bulletin GCP-2026-044 published June 25, 2026. Researcher awarded $75,000 bounty through Google's Vulnerability Reward Program.

// Get alerts for Google Cloud