vulns.co
/
GKData.io MCP

AZAuthorization and tenant boundaries · 2 min read

Google Firefly confused worker authority and storage boundaries

Firefly received a separately identified USD 60,000 award. The case illustrates how delegated worker authority and storage permissions can diverge from caller authorization.

Read the primary source AZAuthorization and tenant boundariesReviewed 2026-10-03

Root cause

Missing caller authorization, unverified worker-result authority and unconstrained storage abstraction crossed service boundaries. The researcher questioned whether a narrowly named field actually limited backend authority.

Demonstrated impact

The researcher demonstrated storage reads and a local test-file write under a production identity. Broader access remained permission-dependent; universal infrastructure compromise is not established.

Lessons for review

  • Editorial lesson: authenticate scheduler callbacks against the assigned worker and bind completion to an immutable task.
  • Editorial lesson: enforce explicit storage capabilities rather than relying on field names; apply resource authorization before delegated execution.

Award and evidence

USD 60,000Bug Bounty · Researcher Reported With Vendor Quote

Separate report award; headline total is not used. Payment is unverified. USD follows the linked official denomination context. No component is counted separately.

Read both primary pages in the cloud browser after search returned no article body. Matched exact report labels to separate timeline awards. No target testing.

  • Researcher narrative is hosted by Google and authored by a researcher who subsequently joined Google; conservatively classified as researcher-reported panel correspondence, without independent payment evidence.
  • Resolution is stated, but deployment date and patch implementation are unspecified.
  • The dollar denomination is inferred from Google’s July 2024 USD program announcement, approximately two years before the awards; it does not prove individual settlement.
  • The article demonstrates requests with a caller session but does not fully specify minimum account prerequisites; missing authorization is not treated as proof of anonymous Firefly access.

Recorded timeline

Published
2026-09-11explicit
Reported
2026-07-14explicit
Awarded
2026-07-24explicit

Sources and provenance

  1. Breaking into Google's GFile for $100k Arvin Shivram (Brutecat), published on Google Bug Hunters · reviewed 2026-10-03
  2. Increasing Google & Alphabet VRP rewards up to $151,515 Sam Erb and Krzysztof Kotowicz, Google · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software