Google Cloud Vertex AI Flaw Enables Model Hijacking and Poisoning Attacks
ID: 46b9ee53-0cab-54c0-a1bf-4a7e18e6237b
STIX ID: report--46b9ee53-0cab-54c0-a1bf-4a7e18e6237b
Feed Name: Cyber Press
A critical design flaw in the Google Cloud Vertex AI Python SDK allowed attackers who know a victim’s project ID to pre-create deterministically named staging buckets, capture model uploads, swap them with malicious pickle payloads in a short race window, and achieve remote code execution and exfiltrate service-account credentials; Unit 42 disclosed the issue as “Pickle in the Middle,” Google issued fixes (randomized bucket naming and ownership checks) and advises upgrading to v1.148.0+ and explicitly setting staging_bucket.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
