Google’s Vertex AI Vulnerability Enables Low-Privileged Users to Gain Service Agent Roles
ID: 6e2915a9-f3ea-5783-acad-343e8579ae89
STIX ID: report--6e2915a9-f3ea-5783-acad-343e8579ae89
Feed Name: cybersecurityNews.com
XM Cyber and related reporting disclose default-configuration vulnerabilities in Google Vertex AI that permit privilege escalation through two paths: a malicious tool call in the Reasoning Engine (leading to RCE and theft of the Reasoning Engine Service Agent token) and insecure default access on Ray head nodes (viewer access enabling a root shell and theft of the Custom Code Service Agent token). Successful exploitation can expose LLM data, chats, and give read/write access to Cloud Storage and BigQuery; recommended mitigations include revoking unnecessary Service Agent permissions, disabling head node shells, validating staged tool code, and monitoring metadata access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
