Google Cloud Split Its Patch Duty in Two

Google Cloud published a multi-bulletin advisory on Aug. 25 that separates customer-side fixes from provider-managed remediation. One bulletin says a critical unauthenticated remote code execution flaw in Next.js and libheif can hit customer workloads on Google Cloud, while other entries cover TPM 2.0 and Intel Trusted Domain Extensions issues Google says it will handle in its own maintenance windows. The Next.js issue works by feeding a crafted image into the app's image-optimization path, where the underlying parser can be made to run attacker-controlled code in the application's context. Google says its backend infrastructure is not directly vulnerable; the exposure sits in the customer app stack, including containers and package versions, so fixing the cloud host does not close that path. For teams running Next.js anywhere, not just on Google Cloud, the important boundary is the same: provider-managed firmware can be cleaned up centrally, but app-layer code and base images remain the customer's problem. If your workload includes libheif, the downstream exposure follows the image-processing library until that stack is rebuilt and redeployed.

Part of the PlainSec briefing for 2026-08-26

Editions

CVEs

Sources