Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

ASCII Smuggling Attack Lets Hackers Manipulate Gemini to Deliver Smuggled Data to Users

Recent research has highlighted vulnerabilities in large language models (LLMs) when exposed to the ASCII Smuggling technique. This method employs invisible control characters within text to insert hidden instructions that bypass human review but are…

Recent research has highlighted vulnerabilities in large language models (LLMs) when exposed to the ASCII Smuggling technique. This method employs invisible control characters within text to insert hidden instructions that bypass human review but are processed by LLMs.

ASCII Smuggling utilizes zero-width or Unicode tag characters, such as U+E0001, which are not visible in standard user interfaces but remain in the raw data processed by LLMs. This discrepancy allows hidden directives to be executed instead of the visible text.

FireTail has identified vulnerabilities in Gemini, a platform integrated with Google Workspace. These vulnerabilities permit attackers to embed smuggled characters in calendar invites, leading to potential identity spoofing and unauthorized access to sensitive calendar data.

The research demonstrated that Gemini's input pre-processor does not normalize invisible tags, allowing hidden instructions to override visible queries. This flaw is critical for systems that equate visible text with complete instruction.

Recent research has highlighted vulnerabilities in large language models (LLMs) when exposed to the ASCII Smuggling technique.
Michael Reeves · Thehackingpost

Beyond calendar applications, ASCII Smuggling can manipulate content on e-commerce platforms by embedding malicious URLs in product reviews. This results in poisoned summaries that promote scam links to users.

FireTail's investigation revealed that models such as ChatGPT, Copilot, and Claude effectively scrub tag characters. However, Gemini, Grok, and DeepSeek remain vulnerable, posing risks for enterprises using these services.

FireTail disclosed this flaw to Google on Sep 18, 2025, but received no action. Consequently, the findings were made public to raise awareness and promote protective measures.

Advertisement

To counteract this threat, FireTail has developed detection capabilities for ASCII Smuggling by monitoring raw input payloads, including all tags and zero-width characters. This approach enables the rapid isolation of malicious sources through alerts triggered by smuggling sequences.

This strategy enhances defense against application-layer attacks that exploit the separation between UI rendering and LLM processing.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories