48 threats catalogued against Google's Agent Payments Protocol v0.2, eight of them High severity, because signed mandates do not cover the pre-authorization context
A 24 August systematic analysis (arXiv 2608.23858) models AP2 v0.2 across five lifecycle phases and five deployment architectures using MAESTRO, producing four threat actors, eleven attack surfaces, and a catalog of 48 threats scored with AIVSS, eight reaching the High band in at least one architecture. The structural gap: AP2's signed Checkout and Payment Mandates protect transaction data after signing, but the A2A messages and MCP tool calls that shape the transaction before authorization sit outside that protection, so a valid signature does not prove the transaction reflects user intent. The authors built a testbed across all five architectures, five proof-of-concept demos covering every High threat, and a deployment-aware scanner mapping threats to static, cross-role consistency, and adversarial checks.
Source
↳ Follow the thread