Google Cloud Vertex AI Allows Attacker to Hijack Victim’s Model and Poison it
ID: 2595f088-803a-53b9-b1ca-ad504a6be608
STIX ID: report--2595f088-803a-53b9-b1ca-ad504a6be608
Feed Name: cybersecurityNews.com
Unit42 disclosed a vulnerability in the Google Cloud Vertex AI Python SDK that allowed attackers to predict and pre-create staging GCS bucket names (bucket squatting) and, because ownership was not verified, intercept model uploads. Attackers could replace model artifacts milliseconds before deployment and achieve remote code execution through Python pickle deserialization, exposing service account tokens and broad cloud-platform access; the issue affected versions 1.139.0 and 1.140.0 and was fully fixed in 1.148.0.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
