Security researcher Justin O’Leary reports that Google initially accepted his report of a privilege-escalation issue in Google Cloud’s Config Connector, assigning it high priority and severity. According to reporting by The Register, a Google security engineer told O’Leary “Nice catch!” after reviewing the bug and indicated that the issue would be worked on by the relevant product team. Google later denied a bounty through its Cloud Vulnerability Reward Program, reversing the earlier posture. In an April 7 message viewed by The Register, a Google Security Bot said the program panel decided the “security impact” did not meet reward criteria and that the behavior is “working as intended,” though it added that the product team might still fix the problem.

The alleged flaw, described as “ConfigConfusion,” concerns whether Config Connector performs an authorization check. O’Leary says that, if an attacker can use an overprivileged Config Connector service account, they could bypass IAM authorization and obtain organization-wide control (roles/owner) across a GCP Organization. Google has not assigned a CVE or issued a fix, and the report remains marked P1/S1 and “in progress (accepted)” nearly three months later. Google says the IAM bypass is only exploitable with Organization Admin access to the Config Connector service account, which would require entry to the environment; it also says such access conflicts with least-privilege practices.