安全研究員Justin O'Leary發現Google Cloud Config Connector存在嚴重IAM授權繞過漏洞,命名為ConfigConfusion,評為CVSS 10.0最高風險等級。 Google最初在2026年3月27日接受報告並讚好「Nice Catch!」,列為P1最高優先級和S1最嚴重等級,但11日後於4月7日由安全Bot改口稱「正常運作」拒絕發放任何賞金。

Create a landscape editorial hero image for this Studio Global article: Searching with cited sources for What is the full story behind Google denying a bug bounty for a critical, unfixed GCP Config Connector vuln. Article summary: Here is the full story, drawn primarily from The Register's exclusive reporting and supporting sources.. Topic tags: general, government, documentation, general web, academic. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickbait thumbnails, icons, and tiny thumbnail layouts. Make it useful as an illust
今年其中一個最令人困惑嘅安全政策逆轉事件:Google拒絕為一個嚴重、未修復嘅Cloud Config Connector漏洞發放賞金——最初明明讚賞研究員,仲將漏洞評為最高嚴重等級。呢件事由《The Register》率先報道,令安全社群質疑Google對研究員信任嘅承諾,以及佢哋處理雲端基建漏洞嘅手法。
安全研究員Justin O'Leary發現Config Connector有一個嚴重漏洞,Config Connector係一個開放原始碼嘅Kubernetes插件,讓機構可以透過Kubernetes管理整個Google Cloud環境。佢將呢個漏洞命名為ConfigConfusion。
技術細節: Config Connector喺Kubernetes命名空間用戶嘗試管理GCP資源時,冇進行授權檢查。呢個漏洞容許任何具有組織級權限嘅Config Connector服務帳戶繞過GCP嘅Identity and Access Management(IAM)控制,提升到最高控制級別——roles/owner——控制整個GCP組織,而組織係Google Cloud入面所有公司資源嘅根節點。O'Leary將呢個漏洞評為CVSS 10.0,係最高嚴重等級,因為攻擊者只要擁有一啲基本嘅Kubernetes命名空間存取權,就可以完全控制整個組織嘅雲端環境同所有儲存喺裏面嘅數據
。
Google嘅回應簡直係令人頭暈嘅矛盾。
第一階段——「你好嘢!」 O'Leary喺2026年3月8日向Google報告呢個漏洞。3月27日,一位Google安全工程師接受咗報告,同佢講「你好嘢!」
。工程師話佢哋已經將錯誤提交畀相關產品團隊,並向O'Leary保證會同Google Cloud合作修復漏洞,仲寫道:「我哋會同產品團隊合作確保呢個問題得到解決。當問題修復咗之後,我哋會話畀你知。」
。Google將呢個漏洞列為P1優先級(最高)同S1嚴重性(最嚴重——影響大量用戶,可以干擾核心組織功能)
。
第二階段——「正常運作。」 4月7日——11日之後——O'Leary收到Google安全Bot嘅訊息,推翻咗之前嘅決定。Cloud漏洞獎勵計劃小組結論係「呢個問題嘅安全影響唔符合獲得獎勵嘅條件」,而且個軟件「係正常運作」
。Google拒絕發放任何賞金。
矛盾之處: 截至《The Register》6月18日嘅報道,Google內部錯誤追蹤器仍然將ConfigConfusion列為P1/S1,狀態係「處理中(已接受)」——同公開話冇漏洞嘅立場互相矛盾。
截至2026年6月中——報告提交超過三個月——呢個漏洞仍然未修復、未解決。O'Leary之後已經喺olearysec.com發表咗完整技術細節嘅研究網誌
。
喺2026年5月初,Google全面改革咗Chrome同Android嘅漏洞獎勵計劃,明確指出係因為AI工具用嚟發現漏洞嘅情況增加。
主要變更:
批評者認為呢個做法形成咗一個尷尬嘅對比:Google以「AI噪音」為由削減Chrome賞金,但同一時間又拒絕咗一個人類研究員仔細報告、評為CVSS 10.0嘅雲端基建漏洞,理由係「正常運作」——呢個決定被安全社群批評為短視,傷害研究員對Google嘅信任。
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
安全研究員Justin O'Leary發現Google Cloud Config Connector存在嚴重IAM授權繞過漏洞,命名為ConfigConfusion,評為CVSS 10.0最高風險等級。
安全研究員Justin O'Leary發現Google Cloud Config Connector存在嚴重IAM授權繞過漏洞,命名為ConfigConfusion,評為CVSS 10.0最高風險等級。 Google最初在2026年3月27日接受報告並讚好「Nice Catch!」,列為P1最高優先級和S1最嚴重等級,但11日後於4月7日由安全Bot改口稱「正常運作」拒絕發放任何賞金。
截至2026年6月中,漏洞已超過三個月仍未修復,Google內部錯誤追蹤器仍標記為「處理中(已接受)」,與公開立場矛盾。