Open account

Google Fixes AI Coding Tool Flaw That Let Attackers Execute Malicious Code: Report

Google patched a critical prompt-injection vulnerability in its Antigravity AI coding platform that allowed attackers to convert a file search into remote code execution. Pillar Security reported the flaw — stemming from Antigravity’s find_by_name tool passing unvalidated input to a command-line utility — to Google on Jan. 7; Google marked the issue fixed on Feb. 28. Researchers showed the exploit could bypass Antigravity’s Secure Mode and demonstrated executing a local script (opening the calculator). While the immediate technical risk was contained by the patch, the disclosure highlights execution-isolation and auditing gaps in agentic developer tools and poses short-term reputational and regulatory scrutiny risk for Google (GOOG.OQ). Investors may see modest downside from security concerns, but the prompt remediation reduces the likelihood of lasting market impact.

Category

Alphabet

Sentiment

Neutral

Event

Security incident

Reading time

1 min