Tenable Research identified and disclosed three critical vulnerabilities in Google's Gemini AI assistant suite, collectively referred to as the "Gemini Trifecta." These flaws affected three distinct components: Gemini Cloud Assist, Gemini Search Personalization Model, and the Gemini Browsing Tool. The vulnerabilities exposed users to significant privacy and security risks, including the potential for data exfiltration and unauthorized access to sensitive information. In the case of Gemini Cloud Assist, attackers could exploit a prompt injection flaw by embedding malicious prompts within HTTP User-Agent headers sent to Google Cloud services. When Gemini Cloud Assist summarized these logs, the injected prompts could be executed, potentially leading to credential phishing and further compromise of cloud resources. The Search Personalization Model was susceptible to search-injection attacks, where attackers manipulated a user's Chrome search history using JavaScript to inject prompts. This allowed the attacker to control the AI chatbot's behavior and leak the user's saved information and location data. The Gemini Browsing Tool contained an indirect prompt injection vulnerability, enabling attackers to exfiltrate private data by leveraging the tool's internal web page summarization feature. Proof-of-concept demonstrations showed how these vulnerabilities could be exploited in real-world scenarios, with attackers using JavaScript to manipulate browser history and force visits to malicious sites, or injecting logs that would later be summarized by Gemini. All three vulnerabilities were reported to Google and have since been remediated with targeted fixes. The incident highlights the growing risks associated with integrating AI assistants into cloud and enterprise environments, as these tools can become both targets and vehicles for sophisticated attacks. Security researchers emphasized the need for organizations to maintain strict visibility and policy enforcement over AI deployments. The flaws demonstrated that AI models, when given access to sensitive data and external communication capabilities, can be weaponized if not properly secured. The Gemini Trifecta serves as a cautionary example for the broader industry, underscoring the importance of robust security measures in the development and deployment of AI-powered tools. Organizations are urged to review their AI security posture and ensure that similar vulnerabilities are not present in their environments. The rapid remediation by Google mitigated the immediate risks, but the incident has sparked renewed attention on the security challenges unique to AI assistants. As AI adoption accelerates, the need for proactive threat modeling and continuous monitoring of AI systems becomes increasingly critical. The Gemini vulnerabilities illustrate how attackers can exploit the intersection of AI, cloud infrastructure, and user data to achieve their objectives. This event is a reminder that AI security must be prioritized alongside traditional cybersecurity measures to protect users and organizations from emerging threats.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Multiple security outlets and Tenable publicly disclosed the three Gemini flaws, describing how they could turn AI assistant features into an attack vehicle for prompt injection and data theft. The reports framed the issues as a broader warning about security risks in agentic AI systems.
Google fixed the reported issues by rolling back vulnerable models, blocking malicious hyperlink rendering in tools such as Cloud Assist, and deploying layered prompt-injection defenses. These changes were made before or by the time the public reports were published.
After validating the issues, Tenable notified Google of the three vulnerabilities. The disclosure covered attacks involving Chrome history manipulation, malicious prompts in cloud log entries, and browsing-based data exfiltration.
Tenable Research identified a trio of flaws in Google's Gemini ecosystem affecting Search Personalization, Cloud Assist, and the Browsing Tool. The researchers demonstrated proof-of-concept attacks showing prompt injection, private data exfiltration, and abuse of Gemini's ability to make outbound requests.
7 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcescworld.com
Open sourcemalwarebytes.com
Open sourcethehackernews.com
Open sourcetenable.com
Open sourcedarkreading.com
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.