logo

ModeLeak: Privilege Escalation to LLM Model Exfiltration in Vertex AI

ID: 3220935c-3207-5cf6-a7a1-1bed6f248e15

STIX ID: report--3220935c-3207-5cf6-a7a1-1bed6f248e15

Feed Name: Palo Alto Networks Unit 42

Threat Score
75/100

Date Published: 2024-11-12

Date Updated: 2026-04-28

Author: Ofir Balassiano and Ofir Shaty

...
...

Unit42 researchers found two serious vulnerabilities in Google Vertex AI: a privilege-escalation via malicious custom jobs that abuse service-agent permissions to access project resources, and a model-exfiltration (model-to-model infection) where a deployed poisoned model can obtain and download other ML and fine-tuned LLM adapter weights; the report includes detailed attack steps, impact analysis, and mitigation recommendations, and notes Google has patched the specific issues disclosed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.