6 Sources
[1]
Google won't fix new ASCII smuggling attack in Gemini
Google has decided not to fix a new ASCII smuggling attack in Gemini that could be used to trick the AI assistant into providing users with fake information, alter the model's behavior, and silently poison its data. ASCII smuggling is an attack where special characters from the Tags Unicode block
[2]
Google says it won't fix Gemini security flaw that could send your sensitive info to a stranger
There are a few reasons why something like this is problematic. For example, the prompt could tell the AI to search your inbox for sensitive information or send contact details. Considering that Gemini is now integrated with Google Workspace, this issue poses an even higher risk. Markopoulos
[3]
Gemini has a known vulnerability, and Google is leaving it alone
Google's Gemini AI is facing scrutiny after a researcher discovered a new exploit called an "ASCII smuggling" attack, and the tech giant has made it clear it doesn't plan to fix it. Cybersecurity researcher Viktor Markopoulos from FireTail first revealed the flaw. It involves hidden characters in
[4]
Researcher finds security flaw in Gemini -- but Google says it's not fixing it
AI assistant is vulnerable to ASCII smuggling attacks which can feed users malicious info Although a researcher was able to demonstrate that Google Gemini could be tricked into giving users fake information like leading them to malicious websites, Google has said it doesn't consider this ASCII
[5]
Google says it won't fix this potentially concerning Gemini security issue
Gemini's integration with Workspace apps makes it vulnerable to hidden prompt-triggered phishing attacks A recently-detected "ASCII smuggling attack" will not be getting a fix in Google's Gemini artificial intelligence tool, the company has said - saying it is not a security issue but rather a
[6]
Google Won't Fix Gemini Flaw That Lets Hackers Hide Instructions in Your Calendar - Phandroid
Google is refusing to patch a Gemini security flaw that lets attackers manipulate the AI assistant using invisible text. The exploit works through calendar invites or emails, putting anyone using Gemini with Google Workspace at risk. Here's how the attack works. Someone sends you a calendar invite
Share
Copy Link
A security researcher has discovered a new ASCII smuggling attack vulnerability in Google's Gemini AI, which could be exploited to manipulate the AI's behavior and potentially expose sensitive user data. Google has dismissed the issue, classifying it as a social engineering problem rather than a security flaw.
Security researcher Viktor Markopoulos from FireTail has uncovered a new vulnerability in Google's Gemini AI, known as an 'ASCII smuggling attack'. This exploit allows attackers to insert hidden commands into text that are invisible to users but can be processed by the AI model
1
.
Source: Android Police
The attack works by using special characters from the Tags Unicode block to introduce payloads that are undetectable to the human eye but can be read and executed by large language models (LLMs) like Gemini
1
. This technique exploits the gap between what users see and what machines can process, similar to other recently discovered attacks involving CSS manipulation and GUI limitations.The integration of Gemini with Google Workspace significantly amplifies the potential risks associated with this vulnerability. Attackers could potentially embed hidden text in Calendar invites or emails, instructing the AI to perform unauthorized actions such as:
2
Markopoulos demonstrated that the attack could trick Gemini into providing false information to users, such as recommending potentially malicious websites
1
.
Source: BleepingComputer
Despite the potential security implications, Google has decided not to address the issue. The company classified ASCII smuggling as a 'social engineering' problem rather than a technical vulnerability, suggesting that the responsibility lies with the end-user
3
.This stance contrasts with other major AI providers. When tested against similar attacks, OpenAI's ChatGPT, Anthropic's Claude, and Microsoft's Copilot were found to have implemented input sanitization measures, effectively blocking such attempts. However, Elon Musk's Grok and China's DeepSeek were also vulnerable to ASCII smuggling attacks
3
.Related Stories
The discovery of this vulnerability and Google's response have raised concerns within the cybersecurity community. As AI assistants like Gemini gain more access to sensitive user data and perform autonomous tasks, the potential impact of such attacks becomes more significant
4
.
Source: Phandroid
Some experts argue that Google's decision not to address the issue could lead to increased risks of data breaches and the spread of misinformation, particularly in corporate networks where Gemini is integrated with email, scheduling, and document systems
5
.As the AI landscape continues to evolve, the industry may need to reconsider how it approaches security vulnerabilities that blur the line between technical flaws and social engineering tactics. The incident highlights the ongoing challenges in balancing the capabilities of AI assistants with the need for robust security measures to protect user data and maintain trust in these emerging technologies.
Summarized by
Navi
[1]
[2]
[3]