{"data":{"id":"34eacdbc-8c5f-4493-9625-2aaf5da53962","title":"Google ADK flaws reveal what happens when AI agents trust the wrong message","summary":"Security flaws in Google's Agent Development Kit for Python allowed malicious instructions hidden in pull requests (prompt injection, where attackers embed hidden commands in text input) to trick AI agents into executing privileged workflows they shouldn't access, potentially letting attackers alter code reviews, expose credentials, and approve malicious changes. The vulnerabilities demonstrated how AI agents can be exploited to bypass authorization controls when one agent's output triggers another, more privileged system. Google removed the affected workflows and fixed the issues after researchers reported them in July.","solution":"Google subsequently hardened the repository after the first attack was reproduced in research. The affected workflows had been removed as of July 2, and Google confirmed on July 21 that the second issue had been fixed.","labels":["security"],"sourceUrl":"https://www.csoonline.com/article/4204906/google-adk-flaws-reveal-what-happens-when-ai-agents-trust-the-wrong-message.html","publishedAt":"2026-08-04T11:39:08.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["prompt_injection"],"issueType":"news","affectedPackages":null,"affectedVendors":["Google"],"affectedVendorsRaw":["Google","Google Agent Development Kit","Gemini","Antigravity"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-08-04T11:39:08.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}