
What happened
A flaw in the Google Cloud Vertex AI SDK for Python allowed an attacker with only a Google Cloud project and the victim's project ID to intercept model uploads. The SDK generated a predictable temporary bucket name; if an attacker created that bucket first in their own project, the victim's upload would go to the attacker's bucket instead. The attacker could then swap in a malicious model that executed code when Vertex AI loaded it. Google shipped the fix in version 1.148.0 on April 15, adding bucket ownership verification.
Why it matters
The attack required no stolen credentials, phishing, or initial foothold—only publicly available information. Once code ran inside the serving container, it could steal OAuth tokens with broad access to other models, TensorFlow artifacts, BigQuery metadata, and internal infrastructure details in the same Google-managed tenant. This is the second bucket-squatting flaw in Vertex AI this year, suggesting a pattern in how the service handles default storage.
What to watch
Update to SDK version 1.148.0 or later immediately. Also set an explicit staging_bucket parameter to a Cloud Storage location you control when uploading models, and check the google-cloud-aiplatform version wherever it runs—notebooks, CI jobs, training pipelines, and production services alike.
Ask the AI about this article →
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
OpenClaw creator Peter Steinberger and co-developers announced OpenClaw 2.0 over the weekend, describing it as…

BHP, the world's largest mining company by market capitalization, has deployed AI across its operations

Team Liquid announced a new five-year extension of its long-running collaboration with Dell Technologies' Alie…

A University of Mississippi study published in Journal of Interactive Advertising found that AI ads succeed wh…

Goldman Sachs Research says AI supply and demand won't balance until the first half of 2028

Lam Research broke ground yesterday on a new lab in Tualatin, Oregon
