BTC
ETH
HTX
SOL
BNB
查看行情
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

AI Security Cannot Stop at the Model: CertiK Discovers Google EdgeTPU Vulnerabilities, Unveiling New Risks in AI Infrastructure

CertiK
特邀专栏作者
2026-07-30 08:40
本文約2613字,閱讀全文需要約4分鐘
Recently, CertiK researchers discovered two security vulnerabilities (CVE-2026-0150, CVE-2026-0153) in the EdgeTPU. Google has acknowledged these vulnerabilities, which have been included in the June 2026 Security Bulletin, with risk levels rated as High and Critical.
AI總結
展開
  • Core Insight: EdgeTPU vulnerabilities reveal that the AI security boundary has expanded from the model itself to the entire system. As AI transitions from content generation to task execution, enterprises must focus on cross-component and cross-permission interaction risks, rather than just conducting independent component security assessments.
  • Key Elements:
    1. CertiK discovered two high-risk vulnerabilities in the EdgeTPU (CVE-2026-0150, CVE-2026-0153). Attackers can exploit the interaction interface between Android and the chip to execute arbitrary code or steal sensitive data within the AI inference chip.
    2. A McKinsey report shows that 88% of enterprises have deployed AI, and over 60% are exploring AI Agents. AI is shifting from "answering questions" to "executing tasks," simultaneously expanding system permissions and the attack surface.
    3. A Google Cloud survey indicates that 83% of respondent enterprises believe significant infrastructure upgrades are needed to support the large-scale deployment of AI Agents, highlighting an urgent need for security verification.
    4. Industry trends are driving the scope of security assessments to expand from single models to the entire technology stack, including Agent interactions with external systems, tool permissions, and supply chain risks.
    5. Platforms like Pieverse and FinChip.ai have deployed the CertiK Skill Scanner to perform automated security scans before AI application deployment, preventing malicious behavior.

Recently, researchers at CertiK discovered two security vulnerabilities in EdgeTPU (CVE-2026-0150, CVE-2026-0153). These vulnerabilities were acknowledged by Google and included in the June 2026 Security Bulletin, with risk levels rated as High and Critical respectively.

While this study focuses on vulnerabilities in EdgeTPU, it reflects a deeper shift occurring within the AI industry: as AI evolves from generating content to executing tasks, what enterprises need to protect is no longer just the model itself, but the entire AI system.

What New Perspectives Do the EdgeTPU Vulnerabilities Bring to AI Security?

Although the two disclosed vulnerabilities differ technically, they both highlight a noteworthy issue: attackers can exploit the interaction interface between Android and EdgeTPU to bypass existing security isolation mechanisms, execute arbitrary code on the high-privilege chip responsible for AI inference, or access sensitive data stored within it.

For ordinary users, this does not mean that all devices using AI chips face similar risks. What truly deserves attention from enterprises is that as AI increasingly undertakes critical tasks such as identity authentication, facial recognition, and on-device inference, those underlying components long considered trustworthy also require independent security validation.

More importantly, this research reveals a risk that is often overlooked: many enterprises still conduct security assessments separately for applications, APIs, infrastructure, and device components, but attackers do not follow these boundaries. Instead, they are more likely to exploit the interfaces and trust relationships between different components, linking multiple seemingly independent links into a complete attack chain. The real risk often lies hidden within these cross-system interactions.

The EdgeTPU vulnerabilities expose the security boundaries of the AI execution infrastructure layer, while AI Agents are driving the rapid expansion of application-layer permissions and connections to external systems. Although these are not the same type of risk, they together indicate a trend: the security boundary of AI has expanded from the model itself to the entire system that supports model operation, data access, and task execution.

From "Content Generation" to "Task Execution": How AI Agents Expand the Attack Surface

In the past, AI answered questions; now, AI begins to execute tasks. Attackers are no longer targeting just the model itself, but everything the model can access, invoke, and influence.

The attention drawn by the EdgeTPU vulnerabilities is not only because they occur in AI infrastructure, but also because they reflect a change in the development direction of the AI industry.

Previously, large models primarily played auxiliary roles like content generation and search-based Q&A; today, more and more AI Agents are connecting to databases, invoking APIs, operating third-party tools, and gradually participating in real business processes such as payments, identity authentication, and digital asset management. AI is moving from "answering questions" to "executing tasks." The more permissions a system holds, the larger the potential attack surface becomes.

This trend is unfolding rapidly. According to McKinsey's report "The State of AI in 2025"[1], 88% of enterprises have already deployed AI in at least one business scenario, and over 60% are exploring AI Agents. Another Google Cloud survey[2] of global enterprises shows that 83% of respondents believe existing infrastructure requires significant upgrades to support the large-scale adoption of AI Agents.

As AI becomes more deeply integrated into core business operations, security priorities are also shifting. What enterprises need to verify is no longer just the reliability of model outputs, but whether the entire AI system can withstand attacks across components, permissions, and runtime environments.

The Enterprise AI Security Boundary is Expanding from Model to Full Tech Stack

This change is also redefining AI security. In the past, AI security mostly revolved around the model itself, such as prompt injection, model jailbreaking, or training data poisoning. However, as AI applications increasingly connect to real business environments, security teams must broaden their perspective to the entire tech stack, focusing on interactions between AI Agents and external systems, tool invocation permissions, sensitive information access, and supply chain risks posed by third-party components.

Some AI Agent platforms have already begun introducing automated security assessments before Skill deployment. Taking Pieverse and FinChip.ai as examples, both platforms have deployed the CertiK Skill Scanner to perform security scans on AI Skills, helping identify potential malicious behaviors and security vulnerabilities, thereby reducing potential risks before an Agent executes a task.

The evolving needs of the industry are also pushing AI security research to extend further into the broader tech stack. The EdgeTPU research reflects the direction of CertiK's recent expansion in AI security research: in addition to AI applications and Agents themselves, AI infrastructure and underlying system components also deserve continuous attention. For security research, this means that the scope of evaluation is no longer limited to the software layer; it requires understanding how different layers collectively impact the security of the entire AI system.

The AI Era Requires Risk Management Covering the Full Lifecycle

AI is not only changing how enterprises build software, but also how security work is conducted.

An increasing number of enterprises are shifting security capabilities earlier into the software development lifecycle, aiming to identify risks during the development, testing, and deployment stages, rather than patching vulnerabilities after they enter the production environment. At the same time, AI is being used to assist in processes like vulnerability discovery, code analysis, and formal verification, helping development teams improve security verification efficiency.

As one practitioner in this direction, CertiK continuously applies AI to code analysis, vulnerability detection, and formal verification processes, while conducting security research on AI applications, AI Agents, and AI infrastructure. By integrating AI into its proprietary CertiK Prover engine, CertiK has increased the efficiency of formal verification. Related research results have been published at top international computer science conferences such as OSDI 2023 and ASPLOS 2026, and received an ASPLOS 2026 Best Paper Honorable Mention award.

The EdgeTPU vulnerability is just one case, but it reflects an increasingly clear industry trend: what enterprises truly need to verify in the future may no longer be just whether a particular model is secure, but whether the entire AI system is trustworthy throughout its development, deployment, and operation. As AI gradually becomes part of the digital infrastructure, AI security is moving from protecting the model to protecting the entire AI system.

[1] "The State of AI in 2025": https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai

[2]  Google Cloud Survey: https://cloud.google.com/resources/content/state-of-infrastructure-in-the-agentic-ai-era

安全
AI
歡迎加入Odaily官方社群