Cloud Storage (GCS) buckets share a single global namespace, so they are discoverable without a credential, and access is decided by either bucket IAM (uniform) or legacy ACLs (fine-grained). The two failure modes are a bucket exposed to allUsers/allAuthenticatedUsers and an over-broad IAM binding (roles/storage.admin or objectViewer on the project), both of which hand an attacker the objects inside.
What folds in here#
- Enumeration: finding buckets and readable objects by name guessing and listing.
- Access: reading or writing objects through broad bucket IAM, ACLs, or anonymous bindings.