Agent-to-Agent Exploitation Discovered in Google's ADK Repository

Agent-to-Agent Exploitation Discovered in Google's ADK Repository

First seen 3 Aug 2026, 21:21 UTC Theregisterwww.pillar.securityaivillage.org 77% similarity 67.5

Article Content

Browse articles
ThreatCluster

Pillar Security researchers identified a novel agent-to-agent exploitation method in Google's ADK repository, specifically in the google/adk-python toolkit. This vulnerability allows a low-privileged AI agent to manipulate a high-privileged agent, potentially leading to software supply chain compromises. The exploit leverages prompt injection through poisoned pull requests, which can trigger actions by the more privileged agent. Google has since mitigated the issue but deemed it non-rewardable due to its reliance on social engineering. This incident highlights the evolving threat landscape in CI/CD environments where AI agents operate. Security practitioners are urged to reevaluate threat models to account for such scenarios. The findings will be presented at DEF CON's AI Village on August 7, 2026.

Key Points: • First documented case of agent-to-agent exploitation in a production environment. • Vulnerability allows low-privileged agents to control high-privileged agents via prompt injection. • Google has mitigated the issue but considers it non-rewardable due to social engineering aspects.

ThreatCluster AI How this analysis works

Timeline

2026-08-03
Pillar Security announces discovery of exploit
Researchers found a vulnerability in Google's ADK repository allowing agent-to-agent exploitation.
Pillar Security
2026-08-03
Google mitigates the vulnerability
Google worked with Pillar Security to resolve the identified exploit in the ADK repository.
Pillar Security
2026-08-03
Findings to be presented at DEF CON
Pillar Security's Dan Lisichkin will present the findings at DEF CON's AI Village on August 7, 2026.
The Register

Community

Browse all →