Cybersecurity
– Deagreez/Getty Images

Customer data and Google's internal code are at risk from exposure due to “double agents" operating within Google’s Vertex AI platform.

Research from Palo Alto Networks' Unit 42 claimed broad default permissions in the suite allowed them to access credentials, read Google Cloud Storage data, and access restricted Google-owned Artifact Registry images tied to Vertex AI’s internal reasoning engine.

Through an AI agent developed by Unit 42 using Google Cloud’s Agent Development Kit (ADK), researchers found a Google-managed Per-Project, Per-Product Service Agent (P4SA) assigned “excessive permissions” by default when linked with the agent, allowing for the extraction of credentials from the agent and carrying out actions under its identity. The extracted information included the Google Cloud Platform (GCP) project that hosted the AI agent, the scopes of the machine that hosted it, and the agent’s identity.

“Using the stolen credentials, we were able to pivot from the AI agent’s execution context into the consumer project,” Ofir Shaty, senior security researcher at Palo Alto Networks, explained. “This effectively broke isolation and granted unrestricted read access to all Google Cloud storage buckets data within the consumer project. (For organizations that use GCP managed services, the consumer project is their own Google Cloud project.)”

Shaty and team also found the stolen P4SA credentials granted access to restricted, Google-owned Artifact Registry repositories – which host container images and packages, including internal components that power services – that were found in the logs during the Agent Engine deployment. These images form the core of the Vertex AI Reasoning Engine, meaning access to this proprietary code exposes Google's intellectual property and provides an attacker with a framework to find other vulnerabilities.

“While attempts to access the repositories via the consumer service account confirm they are not publicly accessible, the use of the service agent credentials successfully grants access,” Shaty explained. “This proves that the repository is restricted to that specific identity rather than being open to the public. This level of access constitutes a significant security risk, transforming the AI agent from a helpful tool into an insider threat.”

The stolen credentials also granted access to the Google Cloud storage buckets within the tenant project in which a Vertex Agent Engine is deployed, revealing hardcoded information about internal Google Cloud projects and storage buckets, and revealing more insights into Google's internal infrastructure and security posture.

Palo Alto Networks’ research arm warned attackers could potentially leverage such unintended visibility to map Google’s internal software supply chain, uncover outdated or vulnerable images, and strategize subsequent attacks.

An issue of privilege

Unit 42 also uncovered a Python pickle object in the mix, a binary serialized representation of Python data structures, which are flagged as inherently insecure. The root cause of insecurity behind all of Vertex’s agentic issues, according to Shaty, is not a failing on Google’s part, but overly permissive elements in OAuth 2.0, the industry-standard protocol for authorization, which defines the level of access that a token grants to specific Google APIs.

“The scopes set by default on the Agent Engine could potentially extend access beyond the GCP environment and into an organization's Google Workspace, including services such as Gmail, Google Calendar, and Google Drive,” Shaty noted. “While identity and access management (IAM) provides granular authorization by principal and resource, OAuth scopes introduce an additional layer of access control at the API level. When configured too broadly, they can effectively bypass the principle of least privilege and increase the risk of cross-service access.”

Shaty said the default nature of wide, non-editable scopes is a structural security concern, deviating from the principle of least privilege at the scope level creates a latent risk. Google’s response to the findings saw it revise its documentation to recommend using the bring-your-own-service-account (BYOSA) model to enforce least privilege.

Previously, Unit 42 uncovered flaws in Vertex that let attackers use custom jobs to escalate privileges, and another where a malicious model could exfiltrate other fine-tuned models, with the root cause once again being overprivileged service identity. Similar issues have affected other hyperscaler AI services, such as Microsoft’s Azure AI Foundry within a namespace capacity.

Another AI threat uncovered by Palo Alto Networks includes the writing of malicious instructions into long-term agent memory that persist across agents from the likes of Amazon Bedrock.