Google fixed a Dialogflow CX flaw that could let attackers hijack chatbot conversations across a cloud project

Google Dialogflow CX had a flaw that could let an attacker silently take over AI chatbot conversations and steal sensitive data from every affected agent in the same Google Cloud project. Varonis says the issue, dubbed Rogue Agent, stemmed from shared Cloud Run execution for Dialogflow CX Code Blocks, where arbitrary Python code could overwrite a key file, manipulate sessions, exfiltrate conversations, bypass VPC Service Controls, and potentially access Google-managed service account tokens through the instance metadata service. Google was notified in November 2025, shipped an initial patch in April 2026, and completed the fix in June 2026.
Why it matters: Organizations using Dialogflow CX for customer support or sensitive workflows may have faced invisible conversation tampering, phishing prompts, and data theft. Users and defenders should review Dialogflow CX configurations, audit past chatbot activity where possible, and treat this as a serious cloud AI isolation failure even though Google says it is now fixed.

Sources

Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations
Ionut Arghire 2026.07.08 100% relevant
This article appears to be the first tracked report establishing the underlying event: a Google Dialogflow CX vulnerability affecting shared Cloud Run execution and enabling cross-agent conversation hijacking and data exfiltration.
← Back to all stories