
2x Google RCE with VRP Legend Brutecat (Ep. 177)
Source: YouTube · Critical Thinking - Bug Bounty Podcast · published Jun 4, 2026 · 1:25:27
Security researcher Brute Cat details how he leveraged stubby RPC exploitation, protobuf manipulation, and IDOR chains to uncover critical vulnerabilities in Google’s infrastructure, resulting in significant bug bounty payouts.
Key Takeaways:
• Brute Cat utilized the X-Goog-Encoded-Response-If-Executable-Base64 header to bypass protobuf restrictions and dump internal workflow execution logs from the Cloud CRM API 10:20
• He identified a filter injection vulnerability in the list_quota_queue endpoint, enabling a binary search to leak UUIDs and establish an IDOR chain linking YouTube channels to account emails 15:45
• The researcher exploited "Generic stubby type task" endpoints to execute arbitrary RPC calls, achieving Remote Code Execution (RCE) by bypassing authentication via duplicate endpoints and ACL misconfigurations 20:10
Brute Cat’s methodology demonstrates that combining obscure header manipulation, filter-based binary searches, and internal RPC access allows for high-impact exploitation of Google’s complex microservices architecture.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
I I don't know. I can't remember any dates or whatever, but I can remember I can remember that weird header. Or that password. I can remember the password of my first domain admin that I popped, you know, like but I can't I can't remember >> remember my I don't remember my own mom's birthday, but I remember I remember this one. >> [music] >> Best part about hacking when you can just, you know, critical thing, right? >> [music] [laughter] [gasps] >> Hey, what's up guys? Before we get into the show, I wanted to mention something super quick from our friends at ThreatLocker and I actually think you all are going to think it's pretty awesome because so much of bug bounty is often, you know, kind of quoted as like, "Yeah, but hackers will never exploit that because they can just get in via fish…