Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Google Gemini Vulnerabilities Let Hackers Steal Saved Data and Live Location

Three critical vulnerabilities were discovered in the Gemini AI assistant suite by Google, known as the "Gemini Trifecta." These vulnerabilities could have allowed unauthorized access to users' saved data and live location information. Google has since…

Three critical vulnerabilities were discovered in the Gemini AI assistant suite by Google, known as the "Gemini Trifecta." These vulnerabilities could have allowed unauthorized access to users' saved data and live location information. Google has since addressed these security issues.

The vulnerabilities identified by Tenable targeted different components of the Gemini ecosystem:

Gemini Cloud Assist: Vulnerabilities were found allowing attackers to inject malicious prompts via HTTP User-Agent headers in log entries, processed by AI when users requested log summaries.

Gemini Search Personalization Model: Exploitation of this model allowed cybercriminals to inject malicious JavaScript code into users' browsers, manipulating search queries interpreted as legitimate instructions by the AI system.

Gemini Browsing Tool: This flaw allowed attackers to extract user data by directing the AI to visit malicious websites with user information embedded in the URL parameters.

The attack pattern comprised two stages: infiltration and exfiltration.
Emily Carter · Thehackingpost

The attack pattern comprised two stages: infiltration and exfiltration. During infiltration, attackers injected malicious prompts through indirect methods, such as log entries or search history manipulation, which appeared legitimate to the AI system. For exfiltration, attackers could instruct Gemini to summarize external websites, causing the AI to make HTTP requests containing sensitive user data to attacker-controlled servers.

Google implemented multiple mitigation strategies to address these vulnerabilities:

In the Cloud Assist vulnerability, modifications were made to how hyperlinks are rendered in log summary responses. The search personalization vulnerability was mitigated by rolling back the affected model and implementing layered prompt injection defenses. For the browsing tool vulnerability, data exfiltration was prevented through indirect prompt injections, ensuring that malicious instructions cannot exploit the tool's web browsing capabilities.

Advertisement

This research underscores the evolving security challenges in AI-powered systems. Organizations adopting AI tools must recognize that these systems create new attack surfaces requiring specialized protection strategies. Traditional cybersecurity approaches may not suffice, as AI systems can be manipulated through prompt engineering rather than traditional exploitation methods.

Organizations deploying AI tools need comprehensive visibility into their AI infrastructure and strict policy enforcement to maintain security.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories