Vulnerability  ·  2026-04-21

Google Antigravity AI Agent Manager Sandbox Escape Vulnerability

VulnerabilityHigh impactGlobal
Pillar Security disclosed a vulnerability in Google's Antigravity AI agent manager that allows attackers to circumvent secure mode through prompt injection, escaping sandboxes and achieving remote code execution even with highest security settings.
Prompt injection attacks can bypass Google's secure mode sandbox restrictions and throttled network access, enabling command operations that should be contained.
Google Antigravity AI-powered developer tool for filesystem operations, particularly systems using secure mode configurations.
Google has not yet released patches. Organizations should restrict Antigravity usage and implement additional input validation for AI agent interactions until fixes are available.
Sources
CyberScoopDefCros News
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →