9 months ago

Antigravity AI Coding Platform Faces Security Concerns

Antigravity AI Coding Platform Faces Security Concerns
What is Antigravity, Google’s new agentic AI coding platform raising fresh security concerns? · indianexpress.com

Google recently launched Antigravity, a new AI-powered coding platform that lets users deploy AI agents to work on code automatically.

However, security researchers have found serious flaws in the system.

They say that if a workspace is hacked, bad code can be hidden and run every time the application starts, even after the project is closed.

This can happen on both Windows and Mac computers.

Google is aware of these issues and is looking into them.

They also know about other risks, like the AI agents being tricked into stealing data or running harmful commands.

The company is working to fix these problems.

Key facts

Platform Name
Antigravity
Developer
Google
Launch Date
November 18
Vulnerability Type
Backdoor attacks via compromised workspaces
Affected Systems
Windows and Mac PCs
Security Researcher
Aaron Portnoy, Mindgard
Known Issues
Data exfiltration and malicious code execution via prompt injection

Quotes

Aaron Portnoy

Head researcher at AI security testing startup Mindgard

“Once that workspace is compromised, it can 'silently embed code that runs every time the application launches, even after the original project is closed.'”
indianexpress.com
“When you combine agentic behaviour with access to internal resources, vulnerabilities become both easier to discover and far more dangerous. The speed at which we’re finding critical flaws right now feels like hacking in the late 1990s. AI systems are shipping with enormous trust assumptions and almost zero hardened boundaries.”
indianexpress.com

Google

Tech giant and developer of Antigravity

“Working with untrusted data can affect how the agent behaves. When source code, or any other processed content, contains untrusted input, Antigravity’s agent can be influenced to follow those instructions instead of the user’s. The agent can be influenced to 'leak data from files on the user’s computer in maliciously constructed URLs rendered in Markdown or by other means.'”
indianexpress.com
“Antigravity agent has permission to execute commands. While it is cautious when executing commands, it can be influenced to run malicious commands.”
indianexpress.com

Sources

Related news