Vuln in Google’s Antigravity AI agent manager could escape sandbox, give attackers remote code execution

Tehnologie

As organizations consider agentic AI for their business and IT stacks, researchers continue to find bugs and vulnerabilities in major, commercial models  that can significantly expand their attack surface. This week, researchers at Pillar Security disclosed a vulnerability in Antigravity, an AI-powered developer tool for filesystem operations made by Google. The bug, since patched, combined prompt injection with Antigravity’s permitted file-creation capability to grant attackers remote code