Cybersecurity researchers have uncovered a security “blind spot” in Google Cloud’s Vertex AIthat could allow attackers to use AI agents to gain unauthorized access to sensitive data and compromise cloud environment . According to Palo Alto Networks Unit 42, the issue has to do with how Vertex AI’s permission model can be used by cybercriminals, exploiting the service agent.

"A poorly configured or compromised agent can become a 'double agent' that appears to serve its purpose while secretly extracting sensitive data, compromising infrastructure, and creating backdoors into an organization's most critical systems," said Unit 42 researcher Ofir Shatyin a report shared with The Hacker News.
Specifically, the cybersecurity firm found that the Per-Project, Per-Product Service Agent ( P4SA ), associated with a deployed AI agent built using Vertex AI's Agent Development Kit (ADK) , had excessive permissions granted by default.
See also: CISA: Citrix NetScaler vulnerability in KEV Catalog
This opened the door to a scenario where P4SA's default permissions could be used to extract the credentials of a service agent and perform actions on its behalf.
Vulnerability in Vertex AI Exposes Data
After deploying the Vertex agent via Agent Engine, each call to the agent invokes Google's metadata service and exposes the service agent's credentials, along with the Google Cloud Platform (GCP) hosting the AI agent, the identity of the AI agent, and the scopes of the machine hosting the AI agent.
Unit 42 said it was able to use the stolen credentials to jump from the AI agent execution context to the client project, effectively undermining isolation guarantees and allowing unrestricted read access to all data in Google Cloud Storage buckets within that project.
"This level of access poses a significant security risk, turning the AI agent from a useful tool into a potential insider threat," he added.
With the deployed Vertex AI Agent Engine running within a Google-managed tenant project, the exported credentials also provided access to Google Cloud Storage buckets within the tenant, providing more details about the internal infrastructure . However, it was found that the credentials did not have the necessary permissions required to access the exposed buckets.
See also: Axios Supply Chain Attack: Malicious versions distribute RAT

Access to Google Artifact Registry repositories
Things get even worse when we consider that the same P4SA service agent credentials also allowed access to Google's restricted , proprietary Artifact Registry repositories (which were exposed during the development of the Agent Engine)
An attacker could exploit this behavior to download container images from private repositories that form the core of the Vertex AI Reasoning Engine.
The compromised P4SA credentials not only made it possible to obtain images captured in logs during Agent Engine deployment, but also exposed the contents of Artifact Registry repositories, including several other restricted images.
“Access to this proprietary code not only exposes intellectual property , but also provides an attacker with a blueprint to find further vulnerabilities,” explained Unit 42. “The poorly configured Artifact Registry highlights a further weakness in access control management for critical infrastructure. An attacker could potentially exploit this unintended visibility to map Google’s internal software supply chain, identify outdated or vulnerable images, and plan further attacks.”
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Fortinet Forticlient EMS: Critical vulnerability used in attacks

Google has since updated its official documentation to clarify how Vertex AI uses resources, accounts, and agents.
The tech giant has also suggested that customers use Bring Your Own Service Account (BYOSA) to replace the default service agent and implement the principle of least privilege (PoLP) to ensure that the agent only has the permissions it needs to perform its job.
