Affected Systems

Google Dialogflow CX agents with Code Block feature enabled, within shared Google Cloud projects. Requires attacker to have edit rights on at least one agent in the project.

Exploitation Status

Discovered by Varonis security researchers. No CVE assigned yet. No public PoC or active exploitation reported at this time.

Business Impact

Attackers with edit access to one Dialogflow CX agent can pivot to compromise other agents in the same GCP project, enabling eavesdropping on live customer conversations, exfiltration of sensitive data processed by chatbots, and injection of malicious responses. High risk for organizations using Dialogflow CX for customer service, support, or internal automation where multiple teams share a GCP project.

Urgency

🟡 Within a week

Recommended Actions

  • Audit Google Cloud IAM permissions for Dialogflow CX agents and restrict edit access to minimum necessary personnel using least-privilege principles
  • Isolate Dialogflow CX agents handling sensitive data into separate GCP projects to prevent lateral movement
  • Review Dialogflow CX audit logs for unexpected agent modifications or Code Block changes since deployment
  • Contact Google Cloud support to confirm patch status and apply any available updates to Dialogflow CX
  • Implement monitoring for unauthorized access attempts or configuration changes to Dialogflow CX agents