Google Vertex AI Flaw Lets Low-Privilege Users Escalate to Service Agent Roles
ID: 48a808d2-6546-5ed7-9528-0b3a743f4265
STIX ID: report--48a808d2-6546-5ed7-9528-0b3a743f4265
Feed Name: GBHackers
Security researchers disclosed critical privilege escalation vulnerabilities in Google Vertex AI that let minimally privileged users hijack Google-managed Service Agent identities. Two attack vectors are described: injecting malicious Python code into Vertex AI Agent Engine tool calls (via aiplatform.reasoningEngines.update) to run code on compute instances and extract the Reasoning Engine Service Agent token, and abusing Ray on Vertex AI head-node interactive shells (via aiplatform.persistentResources.list) to obtain the Custom Code Service Agent token and escalate to root; affected service agent permissions can expose LLM memories, chat logs, GCS and BigQuery data. The report urges revoking unnecessary Service Agent permissions, disabling head-node shells, validating tool code before updates, and monitoring metadata service access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
