news.mlab.sh
Back to the feed
supply-chain

Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting

High
Image: The Hacker News
Summary

A vulnerability in the Google Cloud Vertex AI SDK allowed attackers to hijack model uploads by exploiting predictable bucket naming conventions. Attackers could create a temporary bucket in their own project, intercept the victim's model upload, and execute malicious code within Google's serving infrastructure, potentially stealing sensitive data like OAuth tokens and accessing tenant resources. Google has patched the issue with version 1.148.0, requiring users to update their SDK and explicitly define staging buckets.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.