logo

Google Cloud’s Vertex AI Hit by Vulnerability Enabling Sensitive Data Access

ID: 2b73f5fd-4209-5718-9cab-c4252edf5b35

STIX ID: report--2b73f5fd-4209-5718-9cab-c4252edf5b35

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-04-01

Date Updated: 2026-04-22

Author: Divya

...
...

Unit 42 disclosed a critical flaw in Google Cloud's Vertex AI Agent Engine where default service-agent permissions and the use of pickled AI agents allow an attacker to retrieve P4SA credentials from the metadata service and escalate privileges across GCP, potentially exposing Cloud Storage buckets, Artifact Registry repositories, deployment files, and Google Workspace data; Google worked with Unit 42 to address the issue and recommends using BYOSA and strict least-privilege controls for AI agent deployments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.