Sale of a 0-day exploit for Google Firebase

Dark Web2026-07-21, 09:33
Sale of a 0-day exploit for Google Firebase
For informational purposes only.
Vulnerability type: Stored SSRF
The seller claims to have discovered a stored SSRF vulnerability in Google Firebase's internal server infrastructure. According to the seller, the malicious request is not executed immediately: a canary service set up by the hacker detected a request originating from Firebase approximately a week after the initial exploitation.
A Stored SSRF differs from a regular SSRF in that the data prepared by the attacker is stored in the system, and the server request is initiated later, for example, during background processing, content validation, or the execution of an internal task. This can make it more difficult to detect the source of the attack and allows access to resources that are not directly accessible from the internet. The seller claims that vulnerabilities of this type are significantly more dangerous than standard SSRF vulnerabilities and can be valued at approximately $30,000 in Google's bug bounty program.
Google Firebase is a cloud platform for developing mobile and web applications. It provides developers with databases, file storage, serverless functions, authentication, analytics, push notifications, and other services that run on Google Cloud infrastructure.
Vendors
Google
Products
Google Cloud
Google Firebase