安全研究員 Justin O'Leary 在 Google Cloud Config Connector 中發現一個嚴重的 IAM 授權繞過漏洞(ConfigConfusion),CVSS 評分高達 10.0。 該漏洞允許具備 Kubernetes 命名空間存取權的攻擊者,在無授權檢查的情況下,繞過 GCP 的 IAM 控制,直接取得整個組織的最高管理權限(roles/owner)。

Create a landscape editorial hero image for this Studio Global article: Searching with cited sources for What is the full story behind Google denying a bug bounty for a critical, unfixed GCP Config Connector vuln. Article summary: Here is the full story, drawn primarily from The Register's exclusive reporting and supporting sources.. Topic tags: general, government, documentation, general web, academic. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickbait thumbnails, icons, and tiny thumbnail layouts. Make it useful as an illust
在 2026 年最令人困惑的安全政策大逆轉事件中,Google 拒絕為一個位於其 Cloud Config Connector 中的嚴重且未修補漏洞發放獎金——儘管最初曾讚揚研究員,並將該缺陷列為最高嚴重性等級。此事件由《The Register》率先報導,讓整個安全社群質疑 Google 對研究員信任的承諾,以及其處理雲端基礎設施漏洞的方式。
安全研究員 Justin O'Leary 在 Config Connector 中發現了一個嚴重的缺陷。Config Connector 是一個開源的 Kubernetes 附加元件,讓組織可以透過 Kubernetes 管理其整個 Google Cloud 環境 。他將這個漏洞命名為 ConfigConfusion。
技術細節: Config Connector 在 Kubernetes 命名空間使用者嘗試管理 GCP 資源時,並未執行授權檢查。這使得任何具備組織層級權限的 Config Connector 服務帳戶,都能夠繞過 GCP 的 Identity and Access Management(IAM)控制,並將權限提升至最高層級 roles/owner,進而控制整個 GCP 組織——這是 Google Cloud 中所有公司資源的根節點 。O'Leary 將此漏洞評為 CVSS 10.0(最高嚴重性分數),因為一個僅具備基本 Kubernetes 命名空間存取權的攻擊者,就能取得某組織整個雲端環境及其所有儲存資料的完整管理控制權
。
Google 對此事件的反應充滿了令人錯愕的矛盾。
階段一:「抓得好!」 O'Leary 於 2026 年 3 月 8 日向 Google 回報此漏洞 。3 月 27 日,一名 Google 安全工程師接受了該報告,並回覆他「Nice Catch!」
。該工程師表示已將此錯誤提交給相關產品團隊,並向 O'Leary 保證他們會與 Google Cloud 合作修復此缺陷,寫道:「我們將與產品團隊合作,確保這個問題獲得處理。修復完成後我們會通知您」
。Google 將此錯誤標記為 P1 優先級(最高)以及 S1 嚴重性(嚴重——影響大量使用者,可能擾亂核心組織功能)
。
階段二:「正常運作。」 11 天後的 4 月 7 日,O'Leary 收到一封來自 Google 安全機器人的訊息,推翻了先前的決定 。該機器人表示,Cloud Vulnerability Reward Program 的審查小組判定「此問題的安全影響不符合領取獎勵的標準」,並認為該軟體「運作正常」
。Google 拒絕支付任何漏洞獎金。
矛盾之處: 截至《The Register》6 月 18 日的報導,Google 內部的錯誤追蹤系統仍將 ConfigConfusion 列為 P1/S1,狀態為「處理中(已接受)」——這與其公開主張「不存在漏洞」的立場相互矛盾 。
截至 2026 年 6 月中旬——距離最初報告已超過三個月——該漏洞仍然未獲修補且尚未解決 。O'Leary 隨後在其網站 olearysec.com 上發表了一篇包含完整技術細節的研究部落格文章
。
2026 年 5 月初,Google 全面改革了其 Chrome 和 Android 的漏洞獎勵計畫,明確指出原因是 AI 工具在漏洞發現中的崛起 。
主要變更:
批評者認為,這形成了一個尷尬的對比:Google 以「AI 雜訊」為由削減 Chrome 獎金,同時又以「運作正常」為由拒絕支付一名人類研究員仔細回報的 CVSS 10.0 雲端基礎設施漏洞獎金——安全社群中許多人認為此決定短視近利,且損害了研究員的信任 。
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
安全研究員 Justin O'Leary 在 Google Cloud Config Connector 中發現一個嚴重的 IAM 授權繞過漏洞(ConfigConfusion),CVSS 評分高達 10.0。
安全研究員 Justin O'Leary 在 Google Cloud Config Connector 中發現一個嚴重的 IAM 授權繞過漏洞(ConfigConfusion),CVSS 評分高達 10.0。 該漏洞允許具備 Kubernetes 命名空間存取權的攻擊者,在無授權檢查的情況下,繞過 GCP 的 IAM 控制,直接取得整個組織的最高管理權限(roles/owner)。
O'Leary 於 2026 年 3 月 8 日向 Google 回報此漏洞,Google 安全工程師於 3 月 27 日回覆「Nice Catch!」,並將其列為最高優先級 P1 與最高嚴重性 S1。