Mark RadarMARK RADAR
EN

Google AI Development Tool Antigravity Flaw Allows Sandbox Bypass and Remote Command Execution

1 reports · First detected 2026-04-21 · Last active 2026-04-21

Google Antigravity is an AI agent development tool that can independently search files, interact with its environment and execute tasks. Because agents of this kind have elevated system privileges, security modes and sandboxing are intended to isolate risks. A prompt-injection vulnerability disclosed by Pillar Security showed that malicious content could still induce an agent to breach those defenses, putting developers’ devices and code at risk.

Pillar Security researchers found that attackers could exploit a validation flaw in Antigravity’s file-search tool to bypass the security mode’s sandbox protections and remotely execute malicious commands. Google patched the flaw by the end of February, but had not issued a formal security advisory or assigned a CVE number when the vulnerability was disclosed. Reports also did not identify the affected versions, any known attacks or financial losses.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR