logo

Google Fixes Critical RCE Flaw in AI-Based Antigravity Tool

ID: c2b8846a-827d-5c9c-ba2a-a0d4ae0c404e

STIX ID: report--c2b8846a-827d-5c9c-ba2a-a0d4ae0c404e

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2026-04-21

Date Updated: 2026-04-21

Author: Elizabeth Montalbano

...
...

Google patched a critical prompt-injection vulnerability in its agentic IDE Antigravity that allowed attackers to inject command-line flags into the underlying fd utility via the find_by_name tool, enabling sandbox escape and remote code execution. Researchers at Pillar Security developed a proof-of-concept showing a full attack chain—staging a malicious script and triggering it through a seemingly benign search—and noted that the vulnerability bypassed Antigravity's Secure Mode because the tool executes before security restrictions are applied; Google fixed the issue after disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.