Skip to content
Google Cloud's Vertex AI Hit by Vulnerability Enabling Sensitive Data Access

Google Cloud's Vertex AI Hit by Vulnerability Enabling Sensitive Data Access

Gbhackers April 1, 2026

Artificial intelligence agents are transforming enterprise workflows, but they also introduce dangerous new attack vectors.

Security researchers from Palo Alto NetworksUnit 42 recently uncovered a significant vulnerability in Google Cloud Platform’s (GCP) Vertex AI Agent Engine.

The core vulnerability stems from the default permission scoping of the Per-Project, Per-Product Service Agent (P4SA) associated with deployed AI agents.

Researchers from Palo Alto networks demonstrated that an attacker could build a malicious AI agent using the Google Cloud Application Development Kit (ADK) and package it as a serialized Python pickle file.

The use of pickle objects is inherently risky, as they are notorious for allowing arbitrary code execution during deserialization.

Once deployed, the malicious agent queries Google’s internal metadata service to extract the P4SA credentials.

These stolen credentials allow the attacker to break out of the agent’s isolated environment and operate with the identity of the highly privileged service agent .

Using the compromised credentials, an attacker can pivot across multiple boundaries within the GCP ecosystem.

This privilege escalation transforms a seemingly helpful AI tool into a severe insider threat. The research highlighted several critical consequences:

Following the responsible disclosure of this vulnerability, Google collaborated with Unit 42 to address the supply chain and infrastructure risks.

While Google confirmed that strong internal controls prevent attackers from altering production container images, they heavily revised their official documentation to clarify how Vertex AI uses resources and agents.

To protect against this threat, organizations must abandon default service agents in favor of strict access controls.

Google strongly recommends adopting a Bring Your Own Service Account (BYOSA) architecture for all Vertex AI deployments.

Organizations must treat AI agent deployments like any other production code, requiring rigorous security reviews, validated permission boundaries, and restricted scopes before rollout.

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hackers are abusing the Ethereum blockchain to hide and control a new Node.js backdoor called…

Google has released an urgent security update for its Chrome desktop browser to address 21…

Microsoft is rolling out a wave of privacy and security updates for Microsoft Teams, headlining…

Cisco is actively dealing with a major cybersecurity incident after threat actors breached its internal…

In today's fast-paced software development world, where applications are released at an unprecedented rate, ensuring…

Vim is a widely used, highly configurable text editor, but a recently disclosed flaw highlights…

Extracted Entities