Cybernews
Google Denies Bug Bounty for Critical Kubernetes Flaw Still Unfixed
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Researcher Justin O'Leary discovered a significant vulnerability in Google Cloud's Kubernetes operator, allowing users to bypass Identity and Access Management (IAM) controls. Initially rated as high priority, Google later claimed the issue was 'working as intended' and refused to pay a bug bounty. The flaw, named ConfigConfusion, enables any Config Connector service account with org-level permissions to gain root access to an entire GCP Organization. Despite being flagged as P1/S1 severity, the vulnerability remains unfixed as of June 2026. O'Leary's findings were reported to Google on March 8, 2026, and the communication from Google changed abruptly on April 7, 2026. This situation raises concerns about Google's transparency and the effectiveness of its bug bounty program.
Key Points: • A critical vulnerability in Google Cloud's Kubernetes operator allows unauthorized access. • Google initially acknowledged the flaw but later denied a bug bounty, claiming it was intended behavior. • The vulnerability remains unfixed and is marked with the highest severity rating.