Close Menu
TechurzTechurz
    What's Hot

    Mark Wahlberg is coming to Disrupt 2026

    September 10, 2026

    Maven Robotics wants to steal your robot deployment deal

    September 10, 2026

    India’s Pocket FM doubles revenue run rate to $500M as AI powers 93% of audio content

    September 10, 2026
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Tech Pulse
    • Mark Wahlberg is coming to Disrupt 2026
    • Maven Robotics wants to steal your robot deployment deal
    • India’s Pocket FM doubles revenue run rate to $500M as AI powers 93% of audio content
    • Bending Spoons to buy collaboration tools maker Miro for $1.36B, 90% less than its 2022 valuation
    • Google signs its biggest rice-methane carbon credit deal with Indian startup Mitti Labs
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    TechurzTechurz
    • Home
    • Tech Pulse
    • Future Tech
    • AI Systems
    • Cyber Reality
    • Disruption Lab
    • Signals
    TechurzTechurz
    Home - Cyber Reality - Researchers Disclose Google Gemini AI Flaws Allowing Prompt Injection and Cloud Exploits
    Cyber Reality

    Researchers Disclose Google Gemini AI Flaws Allowing Prompt Injection and Cloud Exploits

    TechurzBy TechurzSeptember 30, 2025Updated:May 10, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Google Gemini AI Flaws
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Sep 30, 2025Ravie LakshmananArtificial Intelligence / Vulnerability

    Cybersecurity researchers have disclosed three now-patched security vulnerabilities impacting Google’s Gemini artificial intelligence (AI) assistant that, if successfully exploited, could have exposed users to major privacy risks and data theft.

    “They made Gemini vulnerable to search-injection attacks on its Search Personalization Model; log-to-prompt injection attacks against Gemini Cloud Assist; and exfiltration of the user’s saved information and location data via the Gemini Browsing Tool,” Tenable security researcher Liv Matan said in a report shared with The Hacker News.

    The vulnerabilities have been collectively codenamed the Gemini Trifecta by the cybersecurity company. They reside in three distinct components of the Gemini suite –

    • A prompt injection flaw in Gemini Cloud Assist that could allow attackers to exploit cloud-based services and compromise cloud resources by taking advantage of the fact that the tool is capable of summarizing logs pulled directly from raw logs, enabling the threat actor to conceal a prompt within a User-Agent header as part of an HTTP request to a Cloud Function and other services like Cloud Run, App Engine, Compute Engine, Cloud Endpoints, Cloud Asset API, Cloud Monitoring API, and Recommender API
    • A search-injection flaw in the Gemini Search Personalization model that could allow attackers to inject prompts and control the AI chatbot’s behavior to leak a user’s saved information and location data by manipulating their Chrome search history using JavaScript and leveraging the model’s inability to differentiate between legitimate user queries and injected prompts from external sources
    • An indirect prompt injection flaw in Gemini Browsing Tool that could allow attackers to exfiltrate a user’s saved information and location data to an external server by taking advantage of the internal call Gemini makes to summarize the content of a web page

    Tenable said the vulnerability could have been abused to embed the user’s private data inside a request to a malicious server controlled by the attacker without the need for Gemini to render links or images.

    “One impactful attack scenario would be an attacker who injects a prompt that instructs Gemini to query all public assets, or to query for IAM misconfigurations, and then creates a hyperlink that contains this sensitive data,” Matan said of the Cloud Assist flaw. “This should be possible since Gemini has the permission to query assets through the Cloud Asset API.”

    Following responsible disclosure, Google has since stopped rendering hyperlinks in the responses for all log summarization responses, and has added more hardening measures to safeguard against prompt injections.

    “The Gemini Trifecta shows that AI itself can be turned into the attack vehicle, not just the target. As organizations adopt AI, they cannot overlook security,” Matan said. “Protecting AI tools requires visibility into where they exist across the environment and strict enforcement of policies to maintain control.”

    The development comes as agentic security platform CodeIntegrity detailed a new attack that abuses Notion’s AI agent for data exfiltration by hiding prompt instructions in a PDF file using white text on a white background that instructs the model to collect confidential data and then send it to the attackers.

    “An agent with broad workspace access can chain tasks across documents, databases, and external connectors in ways RBAC never anticipated,” the company said. “This creates a vastly expanded threat surface where sensitive data or actions can be exfiltrated or misused through multi step, automated workflows.”

    allowing Cloud Disclose exploits flaws Gemini Google injection prompt Researchers
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleDatabricks enters the cybersecurity arena with an AI-driven platform
    Next Article Amazon event 2025 live: Updates on Alexa, Ring, Blink Arc, Fire TV, Kindle, more
    Techurz
    • Website

    Related Posts

    Opinion

    Google signs its biggest rice-methane carbon credit deal with Indian startup Mitti Labs

    September 10, 2026
    Opinion

    This former PG&E engineer is building a ‘Google Maps for the underground’

    August 27, 2026
    Opinion

    AegisAI, founded by former Google security execs, lands $36M to stop AI-driven spear phishing

    July 23, 2026
    Add A Comment
    Latest Tech Pulse

    College social app Fizz expands into grocery delivery

    September 3, 20252,291

    12 Father’s Day E-Card Sites That Are Actually Good

    June 4, 202523

    SolarSquare in talks to raise up to $60M as India’s rooftop solar market draws major VC interest

    May 23, 202622
    Stay In Touch
    • YouTube
    • WhatsApp
    • Twitter
    • Pinterest
    • LinkedIn

    Techurz helps readers stay ahead of digital change with clear, practical, future focused technology intelligence written today,searched tomorrow.

    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Company
    • About Us
    • Contact Us
    • Our Authors / Editorial Team
    • Write For Us
    • Advertise
    Policy
    • Editorial Policy
    • Privacy Policy
    • Terms and Conditions
    • Affiliate Disclosure
    • Cookie Policy
    • Disclaimer
    • DMCA
    Explore
    • AI Systems
    • Cyber Reality
    • Future Tech
    • Disruption Lab
    • Signals
    • Tech Pulse
    • Sitemap

    Join the Techurz Brief

    The future does not arrive suddenly.
    Stay ahead with fast, sharp tech signals.

    Type above and press Enter to search. Press Esc to cancel.