Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Google Cloud Vertex AI SDK Flaw Exposed Model Uploads

Google Cloud Vertex AI SDK Flaw Exposed Model Uploads

Posted on June 16, 2026 By CWS

A significant security flaw was discovered in the Google Cloud Vertex AI SDK for Python, which allowed unauthorized users to hijack machine learning model uploads. This vulnerability, identified by Palo Alto Networks’ Unit 42, posed a threat to those using the SDK, enabling attackers to execute code within Google’s infrastructure. While no real-world exploitation has been reported, users are advised to update to version 1.148.0 or later.

Understanding the Vulnerability

The flaw, termed ‘Pickle in the Middle’ by Unit 42, was reported through Google’s bug bounty program. It allowed attackers with only a Google Cloud project and the target’s project ID to exploit the system. This ID is often publicly available, making the attack feasible without needing credentials or phishing attempts.

The issue originated from how the SDK handled temporary Cloud Storage bucket names for model uploads. If a user didn’t specify a bucket, the SDK created a predictable name using the project ID and region. Attackers could preemptively create a bucket with this name, leading the victim’s SDK to upload models to this malicious bucket instead.

Technical Details and Exploitation

The attack leveraged the fact that bucket names are globally unique. An attacker could replace the victim’s model with a compromised one. When Vertex AI subsequently loaded this model, malicious code could execute within the serving container. This depended on the swift execution of the attack, with a narrow window of approximately 2.5 seconds between the victim’s upload and the model being read by Vertex AI.

Upon successful exploitation, attackers could steal an OAuth token from the serving container’s metadata server. This token had broad access across the Google-managed tenant project, allowing potential access to sensitive data such as TensorFlow models, BigQuery metadata, and other internal resources.

Preventive Measures and Updates

The flaw was reported on March 5, 2026, with Google releasing an initial fix in version 1.144.0 on March 31, introducing a random uuid4 to bucket names. A complete fix was implemented in version 1.148.0 on April 15, adding a bucket ownership verification step to prevent bucket squatting during model uploads.

Users are strongly recommended to update to version 1.148.0 or later to activate these security measures. Additionally, specifying a staging bucket under user control when uploading models can mitigate risks. It is crucial to verify the google-cloud-aiplatform version across all environments, including CI jobs and training pipelines.

This incident marks the second time this year that a predictable bucket name vulnerability has been found in Vertex AI. A similar issue, CVE-2026-2473, was patched in February, addressing cross-tenant code execution risks.

As the cloud landscape continues to evolve, ensuring comprehensive security measures and prompt updates in AI development environments remain essential to safeguard sensitive data and infrastructure.

The Hacker News Tags:bucket ownership, bucket squatting, cloud security, CVE, Google Cloud, machine learning, Python SDK, SDK vulnerability, Unit 42, Vertex AI

Post navigation

Previous Post: Aembit Enhances IAM for Microsoft’s Copilot Studio
Next Post: Arch Linux Halts AUR Signups Amid Major Supply Chain Threat

Related Posts

Apple Warns Old iPhone Users of Web Attacks Apple Warns Old iPhone Users of Web Attacks The Hacker News
20 Popular npm Packages With 2 Billion Weekly Downloads Compromised in Supply Chain Attack 20 Popular npm Packages With 2 Billion Weekly Downloads Compromised in Supply Chain Attack The Hacker News
Iranian Hackers Compromise FBI Director’s Email, Attack Stryker Iranian Hackers Compromise FBI Director’s Email, Attack Stryker The Hacker News
Meta Takes Legal Action Against Global Ad Scams Meta Takes Legal Action Against Global Ad Scams The Hacker News
Meta Adds Passkey Login Support to Facebook for Android and iOS Users Meta Adds Passkey Login Support to Facebook for Android and iOS Users The Hacker News
Apple Urges iOS Update to Combat Exploit Kit Threats Apple Urges iOS Update to Combat Exploit Kit Threats The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit Microsoft Teams to Mask Ransomware Traffic
  • Arch Linux Halts AUR Signups Amid Major Supply Chain Threat
  • Google Cloud Vertex AI SDK Flaw Exposed Model Uploads
  • Aembit Enhances IAM for Microsoft’s Copilot Studio
  • Cal Water Probes Alleged Iranian Hacker Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit Microsoft Teams to Mask Ransomware Traffic
  • Arch Linux Halts AUR Signups Amid Major Supply Chain Threat
  • Google Cloud Vertex AI SDK Flaw Exposed Model Uploads
  • Aembit Enhances IAM for Microsoft’s Copilot Studio
  • Cal Water Probes Alleged Iranian Hacker Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark