VM Escape 0day in KVM Confirmed via Vercel Bug Bounty
Security researcher Paulos Yibelo disclosed a VM escape 0day achieving guest-to-host root compromise in KVM, the industry-standard Linux hypervisor. Vercel CEO Guillermo Rauch confirmed the bug was validated through the Vercel Sandbox bug bounty program.
2026-10-03 ~ 2026-10-04 · 2 related posts
- Full VM escape 0day burned on Vercel's bug bounty: guest-to-host root in standard hypervisors — cramforce · 2026-10-03
- Vercel confirms KVM 0day in Linux virtualization found via its Sandbox bounty program — cramforce · 2026-10-04