Google Dialogflow CX security flaw let researchers create rogue agent to hijack AI chatbots
Security researchers at Varonis discovered a critical vulnerability in Google Dialogflow CX that could have allowed attackers to hijack AI-powered chatbots, steal sensitive user data, and compromise multiple agents within a single Google Cloud project. The flaw, dubbed Rogue Agent, affected organizations using Code Blocks and Playbooks, enabling attackers to read live conversations and send phishing requests. Google patched the issue between April and June 2026, with no evidence of real-world exploitation.