logo

Dialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data Theft

ID: f6e13b9a-c3e6-573b-82d3-cd586116a67c

STIX ID: report--f6e13b9a-c3e6-573b-82d3-cd586116a67c

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2026-07-07

Date Updated: 2026-07-17

Author: Alexander Culafi

...
...

Google patched a critical Dialogflow CX vulnerability called "Rogue Agent" disclosed by Varonis, where abuse of the Code Blocks feature and the dialogflow.playbooks.update permission could let an attacker inject persistent malicious code to exfiltrate conversations and facilitate large-scale phishing; the issue has been fixed and there are no known compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.