BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

AI security cannot stop at the model: CertiK discovers Google EdgeTPU vulnerabilities, unveiling new risks to AI infrastructure

CertiK
特邀专栏作者
2026-07-30 08:40
This article is about 2613 words, reading the full article takes about 4 minutes
Recently, CertiK researchers discovered two security vulnerabilities (CVE-2026-0150, CVE-2026-0153) in the EdgeTPU. These vulnerabilities have been acknowledged by Google and included in the June 2026 Security Bulletin, with risk levels classified as High and Critical respectively.
AI Summary
Expand
  • Core insight: The EdgeTPU vulnerabilities reveal that the AI security boundary has expanded from the model itself to the entire system. As AI evolves from content generation to task execution, enterprises need to focus on cross-component and cross-permission interaction risks, rather than merely conducting independent component security assessments.
  • Key elements:
    1. CertiK discovered two high-risk vulnerabilities in EdgeTPU (CVE-2026-0150, CVE-2026-0153), which allow attackers to exploit the interaction interface between Android and the chip to execute arbitrary code or steal sensitive data within the AI inference chip.
    2. A McKinsey report shows that 88% of enterprises have deployed AI, and over 60% are exploring AI Agents. AI is shifting from "answering questions" to "executing tasks," simultaneously expanding system permissions and attack surfaces.
    3. A Google Cloud survey indicates that 83% of respondent enterprises believe significant infrastructure upgrades are needed to support the large-scale deployment of AI Agents, highlighting the urgent need for security verification.
    4. Industry trends are driving the scope of security assessments to expand from single models to the entire technology stack, including Agent interactions with external systems, tool permissions, and supply chain risks.
    5. Platforms such as Pieverse and FinChip.ai have already deployed CertiK's Skill Scanner to perform automated security scanning before AI application deployment, preventing malicious behavior.

Recently, researchers at CertiK discovered two security vulnerabilities in EdgeTPU (CVE-2026-0150, CVE-2026-0153). These vulnerabilities have been acknowledged by Google and were included in the June 2026 Security Bulletin, with severity levels rated as High and Critical.

This research into EdgeTPU vulnerabilities sheds light on a deeper shift occurring within the AI industry: as AI transitions from generating content to executing tasks, the object that enterprises need to protect is no longer just the model itself, but the entire AI system.

What New Insights Do EdgeTPU Vulnerabilities Bring to AI Security?

Although the two disclosed vulnerabilities have different technical causes, they both highlight a noteworthy issue: attackers can exploit the interaction interfaces between Android and EdgeTPU to bypass existing security isolation mechanisms, execute arbitrary code within the high-privilege chip responsible for AI inference, or access sensitive data within it.

For average users, this does not mean that all devices using AI chips face similar risks. What truly deserves attention from enterprises is that as AI increasingly undertakes critical tasks such as identity authentication, facial recognition, and on-device inference, the underlying components long considered trustworthy also require independent security validation.

More importantly, this research reveals a risk that is easily overlooked: many enterprises still conduct security assessments separately for applications, APIs, infrastructure, and device components. However, attackers do not follow such boundaries. Instead, they are more likely to exploit interfaces and trust relationships between different components, linking seemingly independent steps into a complete attack chain. The real risk often lies hidden within these cross-system boundary interactions.

The EdgeTPU vulnerability exposes the security boundaries of the AI execution infrastructure layer, while AI Agents drive the rapid expansion of application-layer permissions and connections to external systems. While these are not the same type of risk, they together illustrate a trend: the security boundary of AI has expanded from the model itself to the entire system that supports model operation, data access, and task execution.

From "Generating Content" to "Executing Tasks": The Expanded Attack Surface Driven by AI Agents

In the past, AI answered questions; now, AI begins to execute tasks. What attackers target is no longer just the model itself, but everything the model can access, invoke, and influence.

The EdgeTPU vulnerability has drawn attention not only because it occurs in AI infrastructure but also because it reflects a directional shift in the AI industry.

Previously, large language models primarily served auxiliary functions like content generation and search Q&A; today, an increasing number of AI Agents are beginning to connect to databases, call APIs, operate third-party tools, and gradually participate in real business processes such as payments, identity authentication, and digital asset management. AI is moving from "answering questions" to "executing tasks." The more permissions the system has, the larger the potential attack surface becomes.

This trend is accelerating rapidly. According to McKinsey's report "The state of AI in 2025"[1], 88% of enterprises have already deployed AI in at least one business scenario, and over 60% are beginning to explore AI Agents. Another Google Cloud survey of global enterprises[2] shows that 83% of respondent companies believe significant infrastructure upgrades are needed to support the large-scale deployment of AI Agents.

As AI becomes more deeply integrated into core business operations, security focus is also beginning to change. What enterprises need to verify is no longer just whether the model output is reliable, but whether the entire AI system can withstand attacks that cross components, permissions, and runtime environments.

Enterprise AI Security Boundaries Are Expanding from Models to the Full Tech Stack

This shift is also redefining AI security. In the past, AI security was more centered on the model itself, dealing with issues like prompt injection, jailbreaking, or training data poisoning. However, as AI applications increasingly integrate into real business environments, security teams must broaden their perspective to encompass the entire tech stack, focusing on interactions between AI Agents and external systems, tool invocation permissions, access to sensitive information, and supply chain risks introduced by third-party components.

Some AI Agent platforms have already begun incorporating automated security assessments before Skill deployment. For instance, both Pieverse and FinChip.ai have deployed the CertiK Skill Scanner to perform security scans on AI Skills, helping identify potential malicious behavior and security vulnerabilities, thereby mitigating risks before Agent task execution.

The evolving industry demands are also pushing AI security research to extend further across the tech stack. The EdgeTPU research also reflects the expanding direction of CertiK's AI security efforts in recent years: in addition to AI applications and Agents themselves, AI infrastructure and underlying system components warrant continued attention. For security research, this means the assessment scope is no longer limited to the software layer; it requires understanding how different layers collectively impact the overall security of the AI system.

The AI Era Requires Risk Management Covering the Full Lifecycle

AI is not only changing how enterprises build software, but it is also changing how security work is done.

An increasing number of enterprises are shifting security capabilities earlier into the software development lifecycle, aiming to identify risks during the development, testing, and deployment stages, rather than patching vulnerabilities after they enter the production environment. Concurrently, AI is also being used to assist R&D processes such as vulnerability discovery, code analysis, and formal verification, helping development teams improve security verification efficiency.

As a practitioner in this direction, CertiK continuously applies AI to R&D processes including code analysis, vulnerability detection, and formal verification, while conducting security research on AI applications, AI Agents, and AI infrastructure. By integrating AI into its proprietary CertiK Prover engine, CertiK has enhanced the efficiency of formal verification. Related research findings have been published at top international computer science conferences such as OSDI 2023 and ASPLOS 2026, and have received the ASPLOS 2026 Best Paper Honorable Mention award.

The EdgeTPU vulnerability is just one case, but it reflects an increasingly clear industry trend: what enterprises truly need to verify in the future may no longer be just whether a particular model is secure, but whether the entire AI system—from development and deployment to runtime—is worthy of trust. As AI gradually becomes a part of the digital infrastructure, AI security is also evolving from protecting the model to protecting the entire AI system.

[1] The state of AI in 2025: https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai

[2]  Google Cloud Survey: https://cloud.google.com/resources/content/state-of-infrastructure-in-the-agentic-ai-era

Safety
AI
Welcome to Join Odaily Official Community