vulnerability
Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering
High
Summary
A vulnerability in Google’s Agent Development Kit (ADK) for Python allowed an attacker to manipulate low-privileged agents to gain access to high-privilege capabilities, potentially leading to pull request poisoning and remote code execution. This was discovered through a carefully crafted agent-to-agent attack chain, requiring social engineering to exploit.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data