@PhiloGroves This is exactly why CVSS sucks, idk why people bother w/ bugs that already require high privileges. It’s just not impactful. For all of my OSS vuln research, I filter these out.
@Dinosn if you’re interested in hacking google server-side, you should 100% check this out.
@michaeldaltonau did a fantastic job talking about the process of finding bugs through discovery docs :)
@Reelix@goofball1998@KarlsSec The one report there is just what I set to “public” on the bughunters site.
I’m rank 19 on the global leaderboard lol.
If you seriously think I’m a larp feel free to ask any googlers on the VRP discord.
My 2nd RCE in Google Cloud production (Borg) in less than 3 months...
I'm at $600k in total rewards from Google VRP in the past few months. Still can't believe it.