Google Cloud Vertex AI Vulnerability Lets Attackers Take Over and Poison AI Models
ID: b70bd4a4-3e6e-5ffe-afa8-0721ed4bd61a
STIX ID: report--b70bd4a4-3e6e-5ffe-afa8-0721ed4bd61a
Feed Name: GBHackers
A critical vulnerability dubbed “Pickle in the Middle” in the Google Cloud Vertex AI Python SDK allowed attackers to predict and pre-create deterministic staging buckets (bucket squatting), then use a malicious Cloud Function and a narrow race condition to replace uploaded model artifacts with pickled payloads. When Vertex AI deserialized these poisoned models (via joblib/pickle), attackers achieved cross-tenant remote code execution and exfiltrated OAuth tokens; Google released fixes (randomized bucket names and ownership checks) in subsequent SDK versions and patched the issue by April 15, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
