$1 Million Sandbox Challenge Uncovers Linux Kernel Flaws

https://www.securityweek.com/wp-content/uploads/2026/05/Linux-vulnerability-malware.jpeg

A two-week focused sandbox bug-bounty program resulted in 1,285 filings, but none that could access customer data.

The Vercel sandbox, a Firecracker‑based microVM environment, is an isolation tool for untrusted AI‑agent code. For two weeks (August 18 until September 1), Vercel operated a focused bug-bounty program with a $1 million reward pot. It called the program a ‘challenge’ – a challenge to HackerOne hackers (black box targeting) and Trail of Bits engineers (white box targeting) to escape the sandbox.

Time is up, and the results have been published. Vercel received 1,285 reports in two weeks, demonstrating the modern power and speed of researchers working with AI-assistance. “Report triage runs until October 1, but so far we have validated 1 Critical, 7 High, 15 Medium, 49 Low, 19 Informative. ~$325k in committed payouts,” says the firm. None of the reports showed anyone being able to access a real customer’s data –...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE

Read more