Critical risk identified in Vertex AI agents

The flaw stems from default-assigned permissions that could allow attackers to escalate access within cloud projects.

 


Can an artificial intelligence agent become an internal threat without anyone noticing?

New research reveals how a permissions error could open the door to excessive access.


The promise of artificial intelligence in enterprise environments now coexists with a growing concern: the possibility that these very tools may operate beyond control. A recent finding shows how, under certain conditions, an AI agent can become an entity with broad access to sensitive information—without this being apparent to those managing the infrastructure.

Unit 42, Palo Alto Networks’ research team, identified a critical vulnerability in Vertex AI Agent Engine on Google Cloud Platform. The issue lies in the fact that, under default configurations, AI agents may be granted broader privileges than necessary.
If compromised, these agents could effectively act as double agents, with the ability to query, access, and extract sensitive information without restrictions within a corporate environment.

Root of the issue.

The flaw originates from excessive permissions assigned by default to the Per-Project, Per-Product Service Agent (P4SA). This configuration allows a single misconfigured or manipulated agent to become a privileged access point within the affected cloud project, significantly expanding the attack surface.

According to the research, an attacker who compromises one of these agents could gain unrestricted read access to all data stored in the project’s Google Cloud Storage buckets.

This includes sensitive information and other operational resources that, under normal circumstances, should be protected by stricter access controls.

Scope of access.

The analysis also revealed the possibility of accessing internal Google Artifact Registry repositories. From there, experts were able to download container images that are part of the Vertex AI Reasoning Engine, exposing internal infrastructure details and platform components.

This scenario increases the risk of more sophisticated attacks linked to the AI supply chain.

In addition, default OAuth 2.0 permissions were found to be overly broad and not easily modifiable. Under certain conditions, these authorizations could extend the scope of an attack to Workspace services such as Gmail or Drive, depending on the context of the compromised agent.

Response and recommendations.

After identifying the vulnerability, Unit 42 shared its findings with Google and worked closely with its security team. As a result, the company updated its official documentation to more clearly explain how Vertex AI uses resources, accounts, and agents, providing organizations with a better understanding of its operation and permission model.

Researchers warn that, as autonomous agents are adopted at an accelerating pace, organizations must more rigorously review the access levels assigned to these tools.

The autonomy and speed at which they operate mean that a poorly defined permission can quickly escalate into a breach capable of compromising critical information.


Share:
Hosting Web
Most Read