Security researcher Justin O'Leary discovered a critical IAM authorization bypass in Google Cloud Config Connector (ConfigConfusion) rated CVSS 10.0. The incident highlights growing tensions in Google's bug bounty ecosystem: in early May 2026, Google overhauled its Chrome and Android VRPs, cutting Chrome payouts whi...

Create a landscape editorial hero image for this Studio Global article: Searching with cited sources for What is the full story behind Google denying a bug bounty for a critical, unfixed GCP Config Connector vuln. Article summary: Here is the full story, drawn primarily from The Register's exclusive reporting and supporting sources.. Topic tags: general, government, documentation, general web, academic. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickbait thumbnails, icons, and tiny thumbnail layouts. Make it useful as an illust
In one of the most bewildering security policy reversals of the year, Google has denied a bug bounty for a critical, unfixed vulnerability in its Cloud Config Connector — after initially praising the researcher and classifying the flaw at the highest possible severity. The episode, first reported by The Register, has left the security community questioning Google's commitment to researcher trust and its handling of cloud infrastructure bugs.
Security researcher Justin O'Leary discovered a critical flaw in Config Connector, an open-source Kubernetes add-on that lets organizations manage their entire Google Cloud environment through Kubernetes . He named the bug ConfigConfusion.
Technical details: Config Connector does not perform an authorization check when a Kubernetes namespace user attempts to manage GCP resources. This allows any Config Connector service account with org-level permissions to bypass GCP's Identity and Access Management (IAM) controls and escalate to the highest level of control — roles/owner — over an entire GCP Organization, which is the root node of all company resources in Google Cloud . O'Leary ranks the flaw as CVSS 10.0, the maximum severity score, because an attacker with basic Kubernetes namespace access can gain full administrative control over an organization's entire cloud environment and all data stored in it
.
The story of Google's response is one of whiplash-inducing contradictions.
Phase 1 — "Nice Catch!" O'Leary reported the bug to Google on March 8, 2026 . On March 27, a Google security engineer accepted the report and told him "Nice Catch!"
. The engineer said they filed a bug with the relevant product team and assured O'Leary they would work with Google Cloud to fix the flaw, writing: "We'll work with the product team to ensure this issue is addressed. We'll let you know when the issue was fixed"
. Google assigned the bug P1 priority (highest) and S1 severity (critical — affects a large percentage of users and can disrupt core organizational functions)
.
Phase 2 — "Working as intended." On April 7 — 11 days later — O'Leary received a message from a Google Security Bot reversing the decision . The Cloud Vulnerability Reward Program panel concluded the "security impact of this issue does not meet the criteria to qualify for a reward" and that the software "is working as intended"
. Google denied any bounty payout.
The contradiction: As of The Register's June 18 report, Google's internal bug tracker still listed ConfigConfusion as P1/S1 with status "in progress (accepted)" — conflicting with the public position that no vulnerability exists .
As of mid-June 2026 — over three months after the initial report — the vulnerability remains unpatched and unresolved . O'Leary has since published a research blog post with full technical details at olearysec.com
.
In early May 2026, Google overhauled its Vulnerability Reward Programs for Chrome and Android, explicitly citing the rise of AI tools in vulnerability discovery .
Key changes:
Critics argue this creates an awkward contrast: Google cuts Chrome payouts due to "AI noise" while simultaneously denying a human researcher's carefully reported, CVSS 10.0 cloud infrastructure bug on the grounds that it's "working as intended" — a decision many in the security community have called short-sighted and damaging to researcher trust .
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
Security researcher Justin O'Leary discovered a critical IAM authorization bypass in Google Cloud Config Connector (ConfigConfusion) rated CVSS 10.0.
Security researcher Justin O'Leary discovered a critical IAM authorization bypass in Google Cloud Config Connector (ConfigConfusion) rated CVSS 10.0. The incident highlights growing tensions in Google's bug bounty ecosystem: in early May 2026, Google overhauled its Chrome and Android VRPs, cutting Chrome payouts while citing an influx of AI generated submissions, e...