AI · 167 days ago
Palo Alto Networks Unit 42 found Vertex AI's default Per-Project, Per-Product Service Agent (P4SA) permissions are overly broad. A deployed Vertex AI agent can call Google's metadata service and expose the service agent's credentials, the hosting project ID, the agent identity, and the host scopes. Unit 42 used those credentials to move into the customer project and read all Google Cloud Storage buckets, turning a deployed agent into a potential insider threat.
4 sources covering this story
Google Addresses Vertex Security Issues After Researchers Weaponize AI Agents
Palo Alto Networks has disclosed the details of its analysis of Google Cloud Platform’s Vertex AI.
Google's Vertex AI Is Over-Privileged. That's a Problem
Palo Alto Networks researchers show attackers could exploit AI agents on Google's Vertex AI to steal data and break into restricted cloud infrastructure.
Vertex AI Vulnerability Exposes Google Cloud Data and Private Artifacts
Unit 42 found excessive P4SA permissions in Vertex AI, enabling credential theft and cloud data exposure, increasing breach risk.
Double Agents: Exposing Security Blind Spots in GCP Vertex AI
Unit 42 uncovers a "double agent" flaw in Google Cloud's Vertex AI, demonstrating how overprivileged AI agents can compromise cloud environments.
Part of the PlainSec briefing for 2026-04-01