Vercel confirms KVM zero-day with VM escape risk
Vercel has verified a zero-day vulnerability affecting KVM virtualization, reported by security researcher Paulos Yibelo, that allows code running inside a guest virtual machine to achieve root access on the host. The flaw was discovered through Vercel's bug bounty program, which awarded the maximum $50,000. Details of the exploit remain undisclosed, but Vercel confirmed the issue's existence and potential to breach strong isolation boundaries.
- Researcher reported a full VM escape in KVM to Vercel
- Exploit allows guest code to reach host root access
- Vercel awarded $50,000, its largest bug bounty payout
- Exact technical details and affected systems not disclosed
- No customer data exposure confirmed so far
Sources covering this
In this story
More in Cybersecurity
Hackers send extortion message through ASOS app
Hackers took control of ASOS's app notification system and sent a message to users claiming to have breached the company's Snowflake…
ClickFix attacks use browser cache to smuggle payloads
A recent ClickFix campaign is hiding malicious Visual Basic scripts disguised as image files in browser caches on victims' devices,…
Phishing campaign uses fake AI ad tools to steal credentials
Researchers report a phishing operation targeting digital advertising professionals through counterfeit AI tools like ChatGPT, Gemini,…
Nikkei reveals breaches of employee email accounts
Japanese media group Nikkei disclosed that two employee cloud email accounts were breached in separate incidents this year.