Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
  • Home
  • Attack Feeds
  • Vuln in Google’s Antigravity AI agent manager could escape sandbox, give attackers remote code execution  – CyberScoop
AttackFeed by Joe Wagner | Vuln in Google’s Antigravity AI agent manager could escape sandbox, give attackers remote code execution  - CyberScoop

Vuln in Google’s Antigravity AI agent manager could escape sandbox, give attackers remote code execution  – CyberScoop

Posted on April 20, 2026 By djohnson No Comments on Vuln in Google’s Antigravity AI agent manager could escape sandbox, give attackers remote code execution  – CyberScoop
Attack Feeds

As organizations consider agentic AI for their business and IT stacks, researchers continue to find bugs and vulnerabilities in major, commercial models  that can significantly expand their attack surface.

This week, researchers at Pillar Security disclosed a vulnerability in Antigravity, an AI-powered developer tool for filesystem operations made by Google.

The bug, since patched, combined prompt injection with Antigravity’s permitted file-creation capability to grant attackers remote code execution privileges.

The research details how the exploit was able to circumvent Antigravity’s secure mode, Google’s highest security setting for its agents that runs all command operations through a virtual sandbox environment, throttles network access and prohibits the agent from writing code outside of the working directory.

Secure mode is supposed to limit the AI agent access to sensitive systems – and its ability to execute malicious or dangerous acts through shell commands. But one of the file-searching tools used by Antigravity, called “find_by_name,” is classified as a ‘native’ system tool. This means the agent can execute it directly and before protections like Secure Mode can even evaluate command level operations.

“The security boundary that Secure Mode enforces simply never sees this call,” wrote Dan Lisichkin, an AI security researcher with Pillar Security. “This means an attacker achieves arbitrary code execution under the exact configuration a security-conscious user would rely on to prevent it.”

The prompt injection attacks can be delivered through compromised identity accounts connected to the agent, or indirectly by hiding clandestine prompt instructions inside open-source files or web content the agent ingests. Antigravity  has trouble distinguishing between written data it ingests for context and literal prompt instructions, so compromise can be achieved without any elevated access by getting it to read a malicious document or file.

According to a disclosure timeline provided by Pillar Security, the bug was reported to Google on Jan. 6 and patched on Feb. 28, with Google awarding a bug bounty for the discovery.

Lisichkin said this same pattern of prompt injection through unvalidated input has been found in other coding AI agents like Cursor. In the age of AI, any unvalidated input can become a malicious prompt capable of hijacking internal systems.

“The trust model underpinning security assumptions, that a human will catch something suspicious, does not hold when autonomous agents follow instructions from external content,” he wrote.

The fact that the vulnerability was able to completely bypass Google’s secure mode underscores how the cybersecurity industry must start adapting and “move beyond sanitization-based controls.” 

“Every native tool parameter that reaches a shell command is a potential injection point. Auditing for this class of vulnerability is no longer optional, and it is a prerequisite for shipping agentic features safely,” Lisichkin wrote.

The post Vuln in Google’s Antigravity AI agent manager could escape sandbox, give attackers remote code execution appeared first on CyberScoop.

  –

Read More  – CyberScoop 

Post navigation

❮ Previous Post: Vercel’s security breach started with malware disguised as Roblox cheats  – CyberScoop
Next Post: The FTC’s AI portfolio is about to get bigger  – CyberScoop ❯

You may also like

AttackFeed by Joe Wagner | OpenAI’s Mac apps need updates thanks to the Axios hack  - CyberScoop
Attack Feeds
OpenAI’s Mac apps need updates thanks to the Axios hack  – CyberScoop
April 13, 2026
AttackFeed by Joe Wagner | Announcing Pwn2Own Berlin for 2026  - Zero Day Initiative - Blog
Attack Feeds
Announcing Pwn2Own Berlin for 2026  – Zero Day Initiative – Blog
March 12, 2026
AttackFeed by Joe Wagner | Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager  - The Hacker News
Attack Feeds
Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager  – The Hacker News
March 21, 2026
AttackFeed by Joe Wagner | Android Banking Trojan Linked to Cambodia Scam Compounds Hits 21 Countries  - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
Android Banking Trojan Linked to Cambodia Scam Compounds Hits 21 Countries  – Hackread – Cybersecurity News, Data Breaches, AI and More
April 10, 2026

Leave a Reply Cancel reply

You must be logged in to post a comment.

  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.