Wire
CoreBreak exposes 4 agent-tool bypasses
Researchers Hedi Ingber and Aviyam Ivgi presented 4 CoreBreak vulnerabilities across AWS Bedrock AgentCore, Google ADK for Python, and Vercel’s Codex and OpenCode harnesses; in the affected paths, forged tool-call data could reach execution without a model-authorized turn. AWS’s bulletin says its managed service now rejects caller-supplied tool-use blocks, while Google’s CVE record rates the ADK flaw 9.3 Critical and the Vercel advisory requires a patched harness; coverage of the disclosure names the cross-platform pattern. Teams extending policy into the agent harness should bind tool authorization to the exact model event, session and arguments rather than trusting tool-call-shaped input.