OIDC Authentication Vulnerability in Looker by Google Cloud
CVE-2025-12414
What is CVE-2025-12414?
A vulnerability has been identified in Looker that allows attackers to take over user accounts in environments configured with OIDC authentication. This issue arises from improper email address string normalization, leading to potential security breaches in both Looker-hosted and self-hosted instances. While Looker-hosted environments have received necessary mitigations, self-hosted deployments must be promptly updated to defend against this risk. Users are urged to upgrade to the patched versions to ensure the security of their accounts. For more details and downloads, please visit the Looker download page.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Looker Looker-hosted 0 < 24.12.100
Looker Looker-hosted 0 < 24.18.193
Looker Looker-hosted 0 < 25.0.69
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
