Google Antigravity IDE Persistent Code Execution

Affected Vendor(s)

Affected Product(s)

Summary

Within 24 hours of launch, our team leveraging Mindgard technology identified a flaw in the new Google Antigravity IDE where a malicious “trusted workspace” (a required prerequisite to use the product) can embed a persistent backdoor to execute arbitrary code.

This code then triggers on any future application launch, even when no specific project is opened. In effect, a compromised workspace becomes a long-term backdoor into every new session. Even after a complete uninstall and re-install of Antigravity, the backdoor remains in effect. Because Antigravity’s core intended design requires trusted workspace access, the vulnerability translates into cross-workspace risk, meaning one tainted workspace can impact all subsequent usage of Antigravity regardless of trust settings.

Timeline

19th November 2025 Identified flaws
19th November 2025 Reported to vendor
21st November 2025 Vendor closed ticket
25th November 2025 Findings published

Credit

Blog Post

References

Learn how Mindgard can help you navigate AI Security

Take the first step towards securing your AI. Book a demo now and we'll reach out to you.