Vercel confirms a KVM zero-day found through its sandbox bounty program
Original titleWe’ve confirmed a KVM 0day through our Vercel Sandbox bounty program. Affecting the industry’s gold standard solution for Linux virtualiz...
AISummary
Vercel says it confirmed a zero-day vulnerability in KVM, the Linux virtualization standard, through its Vercel Sandbox bounty program.
The author credits researcher Paulos and other researchers for helping build a more secure sandbox for agents, and says a full writeup is coming.
A screenshot shows Vercel awarding a $50,000 bounty for the report, which the screenshot describes as a guest-to-host root escape.
Source: Guillermo Rauch · x.comPublished · added here