Sabitlenmiş Tweet

In hacking, there is that thing that appears at the most unexpected times…
just like magic…✨
Yay, I was awarded a $10,000 bounty on @GoogleVRP for Execute code on the google client.
#googlevrp #Hackerone #Bugcrowd


English
Shobhit Srivastava
540 posts

@sho3hit
Web Security Engineer






Reported a new Google VRP finding discovered with our AI Bug Bounty Agent. 🔥 Issue: unrestricted Google API key exposed in production JS bundle. Impact included: • Billable API abuse (Geocoding/Places/etc.) • API surface enumeration • Internal project name disclosure














