Google has acknowledged two security flaws in its EdgeTPU AI accelerator that researchers at CertiK say could allow an attacker to cross the boundary between Android software and the high-privilege chip used for on-device AI inference. The vulnerabilities, tracked as CVE-2026-0150 and CVE-2026-0153, appeared in Google’s June 2026 Security Bulletin with high and critical severity ratings.
CertiK said the flaws arise from different technical causes but can both be reached through the interface that links Android to EdgeTPU. Successful exploitation could allow arbitrary code execution on the processor or expose sensitive information handled by the chip, according to the security firm.
The findings put attention on a less visible part of AI security: the hardware and software layers that let models access data, execute instructions, and interact with other services. As companies deploy AI systems that can complete tasks rather than simply generate text or images, a weakness in the underlying execution environment can become as consequential as a flaw in an application or model.
Edgetpu flaws target the android-ai processor boundary
EdgeTPU is Google’s purpose-built hardware for running machine-learning workloads efficiently on devices. Such accelerators are designed to process AI inference locally, reducing reliance on cloud infrastructure and helping devices respond more quickly to requests involving vision, language, and other computationally intensive tasks.
CertiK’s description centers on the communication path between Android and that accelerator. The firm said an attacker able to abuse the interface could bypass security isolation intended to separate software components and hardware functions. Isolation is a core protection in modern devices: it limits the ability of one process or subsystem to read another’s data or execute code with its privileges.
A breach at that layer could give malicious code access to a component that handles sensitive inputs for AI workloads. The precise consequences would depend on how an affected device, application, and EdgeTPU services are configured, but the issue places hardware-backed AI processing within the same threat model as operating systems, APIs, and cloud-connected applications.
Google’s high and critical classifications indicate the company considers the vulnerabilities serious enough to warrant attention through its regular Android security update process. Device makers and carriers typically incorporate Android fixes into their own release schedules, which can create variation in when patches reach end users.
Task-running ai expands the security perimeter
The EdgeTPU disclosure arrives as organizations move from experimental generative-AI tools toward agent-style systems that can take actions on behalf of users. These systems may retrieve records from databases, call external APIs, write code, trigger workflows, or interact with third-party tools.
McKinsey’s “The state of AI in 2025” report found that 88% of surveyed organizations were using AI in at least one business function, while more than 60% said they were experimenting with AI agents. Google Cloud, in a separate survey of global enterprises, reported that 83% of respondents believed significant infrastructure upgrades would be required to deploy AI agents at scale.
Those figures describe an environment in which AI security increasingly depends on the full chain around the model. A model can be tested for harmful outputs or prompt-injection susceptibility, yet the system may remain exposed through an overly broad API permission, a compromised third-party integration, an insecure device driver, or a vulnerability in the processor used to run inference.
CertiK argued that security reviews often examine applications, infrastructure, APIs, and device components as separate categories. Attackers do not necessarily operate within those boundaries. They can combine weaker interfaces, authentication gaps, and trust relationships into one route toward a higher-value system.
That approach is particularly relevant for autonomous tools. An AI agent with authority to access internal documents, use a payment workflow, or submit transactions does not need to be “hacked” through its model alone. An attacker may instead target the surrounding tools, credentials, data paths, or the device environment on which the agent operates.
Model risks now sit alongside system and supply-chain threats
Prompt injection, in which malicious instructions attempt to manipulate a model through its inputs, remains a prominent concern for agent builders. Model jailbreaks and training-data poisoning also continue to receive attention. Yet these risks form only part of the attack surface when AI is connected to operational systems.
Permissions determine what an agent can do after it receives an instruction. Data-access controls determine what it can read. Third-party software components and hardware drivers determine whether the environment itself can be trusted. The EdgeTPU vulnerabilities illustrate how a security boundary beneath the application layer can affect systems designed to rely on local AI processing.
For cryptocurrency-related applications, the practical concern is not that the reported bugs automatically endanger wallets or trading platforms. No such direct connection was described in CertiK’s disclosure. The more immediate lesson for developers building AI-assisted financial tools is to limit automated permissions, separate signing functions from general-purpose AI environments, and avoid granting agents unrestricted access to sensitive credentials or transfer functions.
A hardware flaw can add risk where an AI application runs on affected devices and is connected to valuable data or authority. It does not by itself establish that autonomous trading bots, wallets, or decentralized-finance protocols can be remotely hijacked.
Security testing moves closer to deployment
CertiK said some AI-agent platforms have begun scanning “skills” — modular tools that agents use to perform tasks — before deployment. The firm named Pieverse and FinChip.ai as users of its Skill Scanner product, which it said is designed to identify potential malicious behavior and security weaknesses before a skill is allowed to run.
The company also said organizations are shifting security work earlier into development and testing, rather than relying primarily on reviews after software reaches production. That model can include automated code analysis, vulnerability discovery, and formal verification, a technique that mathematically checks whether code meets defined security properties.
CertiK said it has integrated AI capabilities into its CertiK Prover formal-verification engine. The company cited research published at OSDI 2023 and ASPLOS 2026, where related work received an ASPLOS 2026 best paper honorable mention.
The EdgeTPU case gives that development a concrete hardware dimension. AI systems are becoming operational software, and their security depends on each layer that enables action: the model, the tools, the permissions, the operating system, the processor, and the update mechanism that delivers a fix.
For deeper context on AI, security, and crypto markets, explore Toobit Academy’s insights in this guide on web3, AI, and crypto.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

