$ intel.mask2.ca

ADVISORY · 2026-06-16 · SRC UNIT42 · CRITICAL
2026-06-16 critical REL 6/10

Vertex AI SDK vulnerability enables remote code execution through bucket squatting

post-secondaryhealthcarefinanceenergygeneral

Unit 42 identified a critical vulnerability in Google’s Vertex AI Python SDK that allows attackers to achieve remote code execution by exploiting bucket squatting tactics during model uploads. The flaw enables cross-tenant attacks, meaning a threat actor could potentially compromise customers’ environments through this supply chain vector.

Why it matters in Western Canada: Organizations in Western Canada using Google Cloud Vertex AI for machine learning workloads—particularly in healthcare, finance, and energy sectors—face elevated risk if they deploy affected SDK versions without patching.


Summary generated from the original advisory. Read the full source: unit42

Source
https://unit42.paloaltonetworks.com/hijacking-vertex-ai-model/
CVEs
None listed
Tags
vertex-ai, remote-code-execution, supply-chain, google-cloud, bucket-squatting
Provenance
mask2-ti-pipeline (AI-assisted, human-reviewable)