Full VM escape 0day burned on Vercel's bug bounty: guest-to-host root in standard hypervisors

cramforce · x · 2026-10-03

Security researcher Paulos Yibelo disclosed a full VM escape zeroday — guest-to-host root in industry-standard hypervisors — and Vercel's Malte Ubl confirmed it went through their bug bounty program.

"The haters said people wouldn't burn 0day Kernel/KVM CVEs on Vercel bug bounties. They were wrong. It's a new world out there."

A detailed blog post is coming soon.

Original post →

More from Safety

Safety channel →