Gemini Vulnerabilities in Google AI Platform Enable Data and Location Exfiltration

Post Reply
Shane1145
Posts: 1729
Joined: Wed Sep 25, 2024 2:31 pm

Gemini Vulnerabilities in Google AI Platform Enable Data and Location Exfiltration

Post by Shane1145 »

Tenable Research identified three distinct vulnerabilities in Google’s Gemini, showing how modern AI platforms can be leveraged as both targets and vehicles of attack:

Search-injection attacks targeting the Search Personalization Model
Log-to-prompt injection attacks abusing Gemini Cloud Assist’s log summarization features
Exfiltration of saved data and location through the Gemini Browsing Tool
These vulnerabilities demonstrate that the tools designed to streamline user interactions with information are also susceptible to creative attack chains.

https://cyberpress.org/gemini-vulnerabi ... google-ai/
Post Reply