Default Vertex AI Agent Permissions Expose Cloud Data
Palo Alto Networks Unit 42 found Vertex AI's default Per-Project, Per-Product Service Agent (P4SA) permissions are overly broad. A deployed Vertex AI agent can call Google's metadata service and expose the service agent's credentials, the hosting project ID, the agent identity, and the host scopes. Unit 42 used those credentials to move into the customer project and read all Google Cloud Storage buckets, turning a deployed agent into a potential insider threat.