logo

Google Cloud Vertex AI Flaw Enables Model Hijacking and Poisoning Attacks

ID: 46b9ee53-0cab-54c0-a1bf-4a7e18e6237b

STIX ID: report--46b9ee53-0cab-54c0-a1bf-4a7e18e6237b

Feed Name: Cyber Press

Threat Score
82/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Lucas Martin

...
...

A critical design flaw in the Google Cloud Vertex AI Python SDK allowed attackers who know a victim’s project ID to pre-create deterministically named staging buckets, capture model uploads, swap them with malicious pickle payloads in a short race window, and achieve remote code execution and exfiltrate service-account credentials; Unit 42 disclosed the issue as “Pickle in the Middle,” Google issued fixes (randomized bucket naming and ownership checks) and advises upgrading to v1.148.0+ and explicitly setting staging_bucket.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.