安全研究員 Justin O'Leary 發現 Google Cloud Config Connector 存在嚴重權限提升漏洞,可繞過 IAM 控制,讓任何 Kubernetes 命名空間使用者取得整個 GCP 環境的管理員權限。 O'Leary 將此漏洞評為 CVSS 10.0 最高嚴重等級。

Create a landscape editorial hero image for this Studio Global article: Searching with cited sources for What is the full story behind Google denying a bug bounty for a critical, unfixed GCP Config Connector vuln. Article summary: Here is the full story, based primarily on The Register's exclusive report [8] and corroborated by other outlets [2][9].. Topic tags: general, general web, user generated, academic, documentation. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickbait thumbnails, icons, and tiny thumbnail layouts. Make i
以下是根據《The Register》獨家報導及其他媒體報導
整理的完整事件始末。
安全研究員 Justin O'Leary 在 Google Config Connector 中發現一個嚴重的權限提升漏洞。Config Connector 是一個 Kubernetes 操作工具,讓企業可以透過 Kubernetes 指令管理 GCP 資源(如雲端儲存、資料庫、IAM 政策)。
技術細節: 此漏洞允許任何 Kubernetes 命名空間使用者繞過 Google Cloud Platform 的 Identity and Access Management (IAM) 控制。擁有單一 Kubernetes 命名空間基本存取權限的開發人員,可藉此漏洞取得整個組織 GCP 環境的完整管理權限——實際上等於掌控整個雲端帳戶。O'Leary 將此漏洞評為 CVSS 10.0,即最高嚴重等級
。
此案例已歷時將近三個月,至今未發布修補程式,也未支付任何獎金。
初始接受——「好眼力!」
Google 的漏洞獎勵團隊最初處理了這份報告,將其分類為高優先級 / 高嚴重性。一名 Google 代表還對 O'Leary 表示「Nice catch!」(好眼力!)。
獎金被拒——「符合設計預期」
隨後 Google 改變立場,關閉了該報告,並宣稱該行為**「符合設計預期」**——意即不認為這是在計畫規則內的有效漏洞。O'Leary 未獲得任何獎勵。
未修復,仍為開放狀態
截至 2026 年 6 月 18 日,此漏洞仍未解決。Google 尚未修補 Config Connector,也未向 O'Leary 提供任何獎金。
在 2026 年 4 月底 / 5 月初,Google 因應AI 生成提交量大增,全面改革了 Chrome 與 Android 的漏洞獎勵計畫。
O'Leary 的案例雖然屬於 Cloud VRP(而非 Chrome/Android),但卻加劇了研究人員的普遍看法:即使對於手動發現的嚴重漏洞,Google 也在緊縮獎金發放——而與此同時,該公司卻因 AI 報告干擾而公開調降獎金。
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
安全研究員 Justin O'Leary 發現 Google Cloud Config Connector 存在嚴重權限提升漏洞,可繞過 IAM 控制,讓任何 Kubernetes 命名空間使用者取得整個 GCP 環境的管理員權限。
安全研究員 Justin O'Leary 發現 Google Cloud Config Connector 存在嚴重權限提升漏洞,可繞過 IAM 控制,讓任何 Kubernetes 命名空間使用者取得整個 GCP 環境的管理員權限。 O'Leary 將此漏洞評為 CVSS 10.0 最高嚴重等級。
Google 漏洞獎勵團隊最初接受報告並讚賞「好眼力!」,但隨後改口稱該行為「符合設計預期」,拒絕發放獎金。