Vercel has confirmed a KVM zero-day vulnerability after security researcher Paulos Yibelo reported a full virtual machine escape that, he says, allows code inside a guest to gain root access on the host. Full VM escape zeroday (guest>host root in industry standard hypervisors)! More soon pic.twitter.com/dt9AsDO0De— Paulos Yibelo (@PaulosYibelo) October 3, 2026 The discovery came through the Vercel Sandbox bug bounty program, raising concerns about a security boundary used to contain untrusted workloads and AI agents. Yibelo announced the finding on October 3, 2026, describing it as a “Full VM escape zeroday” involving “guest>host root” in industry-standard hypervisors. Vercel CEO Guillermo Rauch separately...
Læs hele artiklen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!