Google Cloud Platform's Vertex AI Agent Engine contains a vulnerability where the Per-Project, Per-Product Service Agent (P4SA) associated with deployed AI agents has overly permissive default permissions. This allows an attacker who compromises a single service agent to extract its credentials and gain privileged access to consumer and producer projects, including sensitive data, restricted images, and source code within Google's infrastructure.
| Vendor | Product | Versions |
|---|---|---|
| google cloud platform vertex ai | — |