BTC
ETH
HTX
SOL
BNB
ดูตลาด
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

AI Security Cannot Be Limited to Models: CertiK Uncovers Google EdgeTPU Vulnerabilities, Revealing New Risks in AI Infrastructure

CertiK
特邀专栏作者
2026-07-30 08:40
บทความนี้มีประมาณ 2613 คำ การอ่านทั้งหมดใช้เวลาประมาณ 4 นาที
Recently, CertiK researchers discovered two security vulnerabilities in the EdgeTPU (CVE-2026-0150, CVE-2026-0153). Google has acknowledged these vulnerabilities, which are included in the June 2026 Security Bulletin with severity levels rated as High and Critical.
สรุปโดย AI
ขยาย
  • Core Insight: EdgeTPU vulnerabilities reveal that the AI security boundary has expanded from the model itself to the entire system. As AI transitions from content generation to task execution, enterprises need to focus on cross-component, cross-permission interaction risks, rather than merely conducting independent component security assessments.
  • Key Elements:
    1. CertiK discovered two high-severity EdgeTPU vulnerabilities (CVE-2026-0150, CVE-2026-0153). Attackers can exploit the interaction interface between Android and the chip to execute arbitrary code or steal sensitive data within the AI inference chip.
    2. A McKinsey report shows that 88% of enterprises have deployed AI, and over 60% are exploring AI Agents. AI is shifting from "answering questions" to "executing tasks," simultaneously expanding system permissions and attack surfaces.
    3. A Google Cloud survey indicates that 83% of respondent enterprises believe significant infrastructure upgrades are required to support the large-scale deployment of AI Agents, highlighting the urgent need for security validation.
    4. Industry trends are driving security assessment targets to expand from individual models to the entire technology stack, including Agent interactions with external systems, tool permissions, and supply chain risks.
    5. Platforms such as Pieverse and FinChip.ai have already deployed the CertiK Skill Scanner to conduct automated security scans before AI application deployment, preventing malicious behavior.

Recently, researchers at CertiK discovered two security vulnerabilities (CVE-2026-0150, CVE-2026-0153) in EdgeTPU. These vulnerabilities have been acknowledged by Google and were included in the June 2026 Security Bulletin, with severity ratings of High and Critical, respectively.

This research on EdgeTPU vulnerabilities highlights a deeper shift taking place in the AI industry: as AI evolves from generating content to executing tasks, the asset enterprises need to protect is no longer just the model itself, but the entire AI system.

What New Perspectives on AI Security Do the EdgeTPU Vulnerabilities Offer?

Although the two disclosed vulnerabilities have different technical causes, they both reveal a noteworthy issue: attackers can exploit the interaction interfaces between Android and EdgeTPU to bypass existing security isolation mechanisms, execute arbitrary code on the high-privilege chip responsible for AI inference, or access sensitive data stored within it.

For average users, this does not imply that all devices using AI chips face similar risks. What truly demands attention from enterprises is that as AI increasingly undertakes critical tasks like identity authentication, facial recognition, and on-device inference, those underlying components long considered trustworthy also require independent security verification.

More importantly, this research uncovers a risk that is easily overlooked: many enterprises still conduct security assessments separately for applications, APIs, infrastructure, and device components. However, attackers do not operate within these boundaries. Instead, they are more likely to exploit interfaces and trust relationships between different components to chain multiple seemingly isolated links into a complete attack path. The real risk often lies hidden within these cross-system boundary interactions.

The EdgeTPU vulnerabilities expose the security boundary at the AI execution infrastructure layer, while AI Agents drive a rapid expansion in application-layer permissions and connections to external systems. These are not the same type of risk, but together they illustrate a trend: the security boundary of AI has expanded from the model itself to the entire system that supports model operation, data access, and task execution.

From "Generating Content" to "Executing Tasks": The Expanded Attack Surface Driven by AI Agents

In the past, AI answered questions; now, AI begins to execute tasks. Consequently, attackers target not just the model itself, but everything the model can access, invoke, and influence.

The attention garnered by the EdgeTPU vulnerabilities stems not only from their location in AI infrastructure, but also because they reflect a change in the direction of the AI industry.

Previously, large models primarily served auxiliary functions like content generation and search-based Q&A. Nowadays, an increasing number of AI Agents are connecting to databases, calling APIs, operating third-party tools, and gradually participating in real business processes such as payments, identity authentication, and digital asset management. AI is moving from "answering questions" to "executing tasks." The more permissions a system has, the larger the potential attack surface becomes.

This trend is accelerating rapidly. According to McKinsey's report "The state of AI in 2025"[1], 88% of enterprises have already deployed AI in at least one business scenario, and over 60% have started exploring AI Agents. Another survey by Google Cloud targeting global enterprises[2] reveals that 83% of respondent companies believe significant infrastructure upgrades are necessary to support the large-scale deployment of AI Agents.

As AI becomes more deeply integrated into core business operations, security focus areas are also shifting. Enterprises no longer just need to verify whether model outputs are reliable; they must ensure the entire AI system can withstand attacks that cross components, permissions, and runtime environments.

The Enterprise AI Security Boundary is Expanding from the Model to the Full Technology Stack

This change is also redefining AI security. Previously, AI security primarily revolved around the model itself, addressing issues like prompt injection, model jailbreaking, or training data poisoning. However, as AI applications increasingly connect to real-world business environments, security teams must broaden their perspective to encompass the entire technology stack. This includes focusing on interactions between AI Agents and external systems, tool invocation permissions, access to sensitive information, and supply chain risks posed by third-party components.

Some AI Agent platforms have already begun incorporating automated security assessments before Skill deployment. For instance, both Pieverse and FinChip.ai have deployed the CertiK Skill Scanner, which performs security scans on AI Skills to help identify potential malicious behaviors and security vulnerabilities, thereby mitigating potential risks before the Agent executes tasks.

Changes in industry demand are also pushing AI security research to extend further across the technology stack. The EdgeTPU research exemplifies a direction CertiK has pursued in recent AI security studies: besides AI applications and Agents themselves, AI infrastructure and underlying system components also warrant continuous attention. For security research, this means evaluation targets are no longer limited to the software layer; it requires understanding how different layers collectively impact the security of the entire AI system.

The AI Era Demands Risk Management Covering the Full Lifecycle

AI is not only changing how enterprises build software, but also transforming how security work is conducted.

An increasing number of enterprises are shifting security capabilities earlier into the software development lifecycle, aiming to identify risks during development, testing, and deployment phases, rather than patching vulnerabilities after they enter the production environment. Simultaneously, AI is being utilized to assist in workflows like vulnerability discovery, code analysis, and formal verification, helping development teams improve the efficiency of security verification.

As one practitioner in this direction, CertiK continuously applies AI to R&D processes such as code analysis, vulnerability detection, and formal verification, while conducting security research focused on AI applications, AI Agents, and AI infrastructure. By integrating AI into its proprietary CertiK Prover engine, CertiK has enhanced the efficiency of formal verification. The related research findings have been published at top international computer science conferences such as OSDI 2023 and ASPLOS 2026, and received the ASPLOS 2026 Best Paper Honorable Mention award.

The EdgeTPU vulnerability is just one case, yet it reflects an increasingly clear industry trend: what enterprises truly need to verify in the future may no longer be just whether a specific model is secure, but whether the entire AI system is trustworthy throughout its development, deployment, and operational lifecycle. As AI gradually becomes part of the digital infrastructure, AI security is also moving from protecting the model towards protecting the entire AI system.

[1] The state of AI in 2025: https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai

[2]  Google Cloud Survey: https://cloud.google.com/resources/content/state-of-infrastructure-in-the-agentic-ai-era

ความปลอดภัย
AI
ยินดีต้อนรับเข้าร่วมชุมชนทางการของ Odaily
กลุ่มสมาชิก
https://t.me/Odaily_News
กลุ่มสนทนา
https://t.me/Odaily_GoldenApe
บัญชีทางการ
https://twitter.com/OdailyChina
กลุ่มสนทนา
https://t.me/Odaily_CryptoPunk
ค้นหา
สารบัญบทความ
ดาวน์โหลดแอพ Odaily พลาเน็ตเดลี่
ให้คนบางกลุ่มเข้าใจ Web3.0 ก่อน
IOS
Android