Vercel has confirmed a zero-day vulnerability in KVM, the Linux virtualization technology that underpins much of the cloud. Independent security researcher Paulos Yibelo found it and reported it through the company's Vercel Sandbox bug bounty program.
Yibelo announced the finding on October 3, calling it a full VM escape zero-day that goes from guest to host root in industry-standard hypervisors. In other words, code running inside a guest virtual machine could break out and gain root access on the host machine. Vercel CEO Guillermo Rauch then confirmed the KVM zero-day and said a full technical write-up would follow.
Vercel awarded Yibelo $50,000, the maximum payout per report in its Sandbox challenge. The public HackerOne program offered up to $1 million in total rewards, and the top payout is reserved for flaws that let an attacker read or modify another tenant's data.
Vercel Sandbox runs each sandbox in its own Firecracker microVM on a bare-metal Amazon EC2 host, and Vercel treats the microVM, not the container, as the main security boundary. A KVM-level flaw matters because Firecracker itself relies on KVM.
Neither Yibelo nor Vercel has yet explained the exploit chain or named the affected versions, and no CVE or public patch has been reported. For now this is a confirmed vulnerability report, not confirmed widespread exploitation. Operators who rely on KVM isolation should watch for Vercel's write-up and their Linux vendors' advisories.
For more on AI, cybersecurity and marketing technology, visit SalesGarners and MarTech360 Hub.
