A KVM flaw validated through the bounty program
Vercel has confirmed a KVM zero-day reported through its Sandbox bounty program. Researcher Paulos Yibelo describes an escape from a guest virtual machine to root access on its host. Vercel's confirmation concerns the reported vulnerability; a full technical account of the escape and its affected systems has not yet been released.[1], [2]
Yibelo and Vercel chief executive Guillermo Rauch made their public statements on October 3. Rauch said a full write-up would follow. Cyber Security News reported the confirmation the next day and described a bounty notification showing a $50,000 award, identified as the program's maximum payment for one finding. The award category covers breaches of customer isolation, including possible access to another customer's data or code execution. Access to another customer is among the category's severe breach criteria. Actual theft of customer information has not been confirmed, and validation of the vulnerability does not establish such a theft.[1]
