A crafted prompt to a low-privilege Google ADK agent could be used to pass a malicious
A crafted prompt to a low-privilege Google ADK agent could be used to pass a malicious hand-off comment to a privileged agent. The post Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering
Original Disclosure
https://www.securityweek.com/gemini-agent-to-agent-attack-e…
Severity
medium
Sector
other
Disclosure date
August 4, 2026
Indexed
18 hours, 36 minutes ago