logo

Transitive Access Abuse - Data Exfiltration via Document AI by Kat Traxler

ID: eaeced04-767f-54c8-b515-56386102ee00

STIX ID: report--eaeced04-767f-54c8-b515-56386102ee00

Feed Name: Vectra AI Blog

Threat Score
75/100

Date Published: 2024-09-16

Date Updated: 2026-05-01

...
...

**TLDR:** The Document AI service auto-assigns a Google-managed service agent with broad project-level Cloud Storage permissions, allowing batch processing jobs to read and write any Cloud Storage objects in the same project and enabling data exfiltration via transitive access abuse; the report provides PoC Terraform modules, a detailed disclosure timeline with Google, and mitigation recommendations such as project segmentation and org policy constraints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.