www.darkreading.com 8/5/2026, 6:21:57 PM · external

Flaws in Google APK for Python Unlock Agent-to-Agent Attack

Flaws in Google APK for Python Unlock Agent-to-Agent Attack
Developing story vulnerability 2 articles tracked
Google Agent SDK flaw enables secret leakage and pull request tampering
CyberSIXT Evidence Panel
Primary Source pillar.security

GOOGLE has resolved vulnerabilities in its open-source Agent Development Kit (ADK) for Python, which were exploited to allow low-privileged AI agents to execute commands intended for high-privileged agents. Discovered by Pillar Security, these flaws demonstrated a new attack vector, potentially compromising the software supply chain through 'agent-to-agent' exploitation. The attack exploited prompt injections via GitHub pull requests.

Google fixed the issues after being reported in June, with remediation completed in July. Researchers call for better governance of AI agents to prevent similar exploitation in the future.

View Primary Source Via www.darkreading.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline