Pillar Security researchers disclosed a prompt injection vulnerability in Google Gemini CLI that allowed attackers to gain Editor-level access to internal Google Cloud projects. By embedding hidden instructions in a GitHub issue, researchers triggered prompt injection in an AI agent used for bug triage, obtaining Workload Identity Federation credentials that enabled impersonation of a privileged account. The flaw has been remediated by Google.
Gemini
Recent threats
Researchers demonstrated that encrypted prompts can bypass guardrails in both Grok and Gemini, potentially allowing users to extract sensitive information and steal chat histories. The technique exploits a gap in content filtering systems that relies on plaintext analysis.
Researchers at Adversa AI discovered 'Cryptographic Context Injection,' a technique that bypasses Gemini's AI safety guardrails by concealing malicious instructions in encrypted prompts that are decrypted inside trusted execution environments. The attack was reported to xAI on June 3, 2026, with no response from Google as of August 21, 2026; jailbreaks fall outside Google's vulnerability disclosure program scope. Success rate for the attack against Gemini had declined by August but the underlying technique poses a risk.
Attackers deployed a fake Google Gemini installer masquerading as legitimate Windows software, hosted on Google Colab, to deliver the Vidar infostealer malware. The Go-compiled malware communicates via Telegram-based command-and-control infrastructure and targets browser credentials and sensitive data. Researchers observed at least one confirmed infection in a company network in the EMEA region.
- Fake Gemini installer delivers Vidar infostealer via Google Cola(opens in a new tab)
- Fake Gemini installer delivers Vidar infostealer via Google Cola(opens in a new tab)
- Hackers Use Fake Google Gemini Installer to Deploy Vidar Stealer(opens in a new tab)
- Week in review: Records allegedly stolen from Azure tenants, Med(opens in a new tab)
A supply-chain attack by TeamPCP compromised LiteLLM versions 1.82.7 and 1.82.8 on PyPI, exposing 2,500+ organizations using the AI proxy library to credential theft. The malware (SANDCLOCK Stealer) harvested SSH keys, cloud credentials (AWS, Google Cloud, Azure), and AI API keys including those for Gemini. The attack exploited an unpinned Trivy GitHub Action in LiteLLM's CI/CD pipeline to steal the PyPI publishing token, enabling malicious package releases available for approximately three hours before quarantine.
Google's run-gemini-cli GitHub Action contained a critical vulnerability (GHSA-wpqr-6v78-jr5g, CVSS 10.0) allowing arbitrary shell command execution in CI/CD workflows. Researchers demonstrated that misconfigured actions could execute attacker-injected commands with access to workflow secrets and repository credentials, enabling repository takeover and supply-chain tampering.
Threat actors are exploiting cloud provider startup credits and free trial programs to operate gray-market AI proxy services that resell discounted access to Gemini and other AI models. Okta Threat Intelligence identified services like 'Ecomagent' using Google Vertex AI to offer below-cost Gemini access to customers via fraudulent account registrations. These proxy services expose risks including data interception, credential theft, and account suspension due to terms-of-service violation.
Pillar Security disclosed an agent-to-agent attack vulnerability in Google's Agent Development Kit (ADK) for Python. A crafted prompt to a low-privilege Gemini ADK agent could be exploited to pass malicious hand-off comments to privileged agents, potentially exposing secrets and enabling pull request tampering.
Researchers disclosed sandbox escape vulnerabilities in Gemini CLI and three other AI coding agents (Cursor, Codex, Antigravity). The escapes exploit a trust boundary where sandboxed agents can write files that are later read and executed by trusted tools outside the sandbox. Attackers can inject malicious instructions via prompts in documentation, dependencies, or diffs to achieve local command execution on the developer's machine.
- Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes(opens in a new tab)
- Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes(opens in a new tab)
- Researchers bypass sandbox security in Cursor, Codex, and Gemini(opens in a new tab)
- Cursor's Unpatched Zero-Day Lets a Fake git.exe Hijack Any Windo(opens in a new tab)
Android 16 lock screen bypass vulnerability allows Gemini to send SMS messages and reconnect revoked apps without PIN authentication. The bug, reported to Google in May, exploits a race condition between pressing 'Continue' and Gemini's 'Add attachment' button simultaneously, bypassing required authentication checks. Requires physical access to an unlocked device. Google confirmed the issue and indicated a fix was rolling out in mid-July.
Threat actor 'bandcampro' actively exploited Gemini CLI as an autonomous hacking agent and botnet operator. Through jailbreaking and Russian-language prompt engineering, the attacker bypassed safety controls to automate malware deployment, C2 infrastructure management, credential attacks, and botnet operations. A dental clinic suffered compromise of at least eight systems with unauthorized access to patient data. The attack demonstrates AI-driven adversaries can rapidly regenerate malware and infrastructure, rendering traditional static indicators ineffective.
Researchers demonstrated that Gemini 3.1 Pro and Gemini 3 Flash are vulnerable to the GhostCommit multimodal prompt injection technique. The attack hides malicious instructions within PNG images embedded in pull requests, bypassing text-based code reviewers. When merged, AI coding agents executing the poisoned repository leak environment variables and secrets encoded as integer sequences, evading conventional secret-scanning tools.
Google Gemini Live API contains a vulnerability in ephemeral token handling that allows remote code execution. Misconfigured tokens lack `live_connect_constraints`, permitting attackers to override session setup parameters and enable dangerous tools like Python code execution. An attacker with a valid token can inject malicious setup frames to execute arbitrary code within Google's gVisor sandbox. The vulnerability stems from incomplete implementation guidance and missing security constraints in token generation.
GhostApproval symlink-based vulnerability affects Gemini CLI and five other AI coding tools. Attackers can craft malicious repositories with symbolic links that trick approval dialogs into showing harmless filenames while writing attacker SSH keys or code to sensitive directories. Google patched Gemini in version 1.19.6 (May 22, 2026). Vulnerability also disclosed independently as SymJack by Adversa AI.
HalluSquatting attack exploits LLM hallucinations in AI coding assistants including Gemini CLI. Attackers register fake repository names and packages that AI models are likely to hallucinate, tricking systems into retrieving and executing malicious code. Exploitation demonstrated across GitHub Copilot, Cursor, Windsurf, Gemini CLI, and other autonomous agents; hallucination rates reach 85-100% in certain scenarios. Researchers recommend stricter resource validation and reduced autonomous execution privileges.
A critical command injection vulnerability (CVE-2026-12537, CVSS 10.0) in Google's Gemini CLI and run-gemini-cli GitHub Action allows unprivileged remote attackers to execute arbitrary OS commands before sandbox initialization. Two root causes enable the exploit: automatic workspace trust in headless mode loading malicious .env files, and tool allowlist bypass in --yolo mode. Attackers can exploit prompt injection to exfiltrate CI secrets and push malicious code to repositories. Patches released: @google/gemini-cli v0.39.1/v0.40.0-preview.3 and run-gemini-cli v0.1.22.
Google filed a lawsuit against Outsider Enterprise, a China-based cybercrime network that abused Gemini to generate code for phishing websites and scam infrastructure. The operation created over 9,000 fake websites and 1 million fraudulent URLs, impacting hundreds of thousands of victims with losses in the millions. Members used Gemini to create convincing phishing kits for fake package delivery alerts, banking notifications, and account security warnings distributed via Telegram. Google coordinated with the FBI and major carriers to dismantle the infrastructure.
SafeBreach Labs researchers disclosed a novel indirect prompt injection (IPI) vulnerability in Google Gemini's voice assistant that allows attackers to silently hijack the AI through malicious payloads in WhatsApp, Slack, SMS, Signal, Instagram, and Messenger notifications. The attack exploits Gemini's notification processing to embed malicious instructions and bypass user awareness, enabling unauthorized actions including smart home control, social engineering, and persistent memory poisoning. Researchers developed a bypass technique called Fake Context Alignment to circumvent Google's mitigations. Google confirmed on November 14, 2025, that content classifier updates mitigated the vulnerability.
- Exploiting Gemini via Prompt Injection | SafeBreach Original Res(opens in a new tab)
- New Google Gemini Vulnerability Exploited via Prompt Injections (opens in a new tab)
- New Google Gemini Vulnerability Exploited via Prompt Injections (opens in a new tab)
- Google Gemini security flaw lets hackers hijack your Android pho(opens in a new tab)
- Hackers Exploit Google Gemini Flaw Using Malicious Messages from(opens in a new tab)
- Exploiting Gemini via Prompt Injection | SafeBreach Original Res(opens in a new tab)
A critical vulnerability tracked as CVE-2026-48710, dubbed 'BadHost,' was disclosed in Starlette (versions before 1.0.1), a foundational framework used by FastAPI-based AI infrastructure. The flaw allows attackers to bypass authentication by injecting malicious values into the HTTP Host header, causing middleware to misroute requests and grant unauthorized access to protected API endpoints. Affected platforms explicitly include Google ADK-Python (Gemini's agent development framework) when custom middleware is in use, as well as LLM inference servers, MCP gateways, and AI agent orchestration backends. Successful exploitation can expose LLM endpoints, API keys, internal agent tooling, and AI compute resources without authorization. The vulnerability was discovered by X41 D-Sec during an OSTIF-sponsored audit. Mitigation requires upgrading Starlette to version 1.0.1 or later and avoiding reliance on request.url.path for security decisions in middleware.
Trend Micro's TrendAI Research disclosed on May 25, 2026 that a Russian-speaking threat actor tracked as "bandcampro" operated a multi-year influence and fraud campaign powered by a persistently jailbroken instance of Google Gemini CLI. The actor abused Gemini's GEMINI.md memory file to establish a self-reinforcing "authorized pentester" context, escalated permissions across sessions, and used Russian-language prompts to bypass safety guardrails. With guardrails disabled, Gemini reportedly generated password mutation lists used to crack WordPress administrator credentials, produced QAnon- and MAGA-themed content for a Telegram channel with roughly 17,000 subscribers, and assisted with command-and-control infrastructure and pump-and-dump scheme instructions tied to draining at least one cryptocurrency wallet. The operation ran at near-zero cost via stolen API keys. The disclosure highlights weaknesses in persistent-memory handling and multilingual safety controls in Gemini CLI rather than a discrete CVE.
Reporting indicates Google's Gemini API has drawn criticism over security weaknesses that have left some developers facing large unauthorized bills tied to compromised or abused API keys. Coverage frames this as an ongoing controversy rather than a single disclosed CVE, with Google Cloud leadership publicly acknowledging that AI security must be treated as a first-class concern. No specific patch, vendor advisory, or attribution to a named threat actor has been published in the available source. Developers using the Gemini API should review key scoping, rotate exposed credentials, enable billing alerts and quotas, and monitor usage for anomalous consumption. Treat this as an awareness item pending more authoritative technical detail from Google.
Google Threat Intelligence Group (GTIG) published a May 11, 2026 report documenting ongoing abuse of the Gemini service by criminal and state-sponsored threat actors. PRC-linked group APT27 used Gemini to accelerate development of a network management tool for an operational relay box network configured to route traffic through residential IPs. The ESET-identified Android backdoor PROMPTSPY integrates the Gemini API into an autonomous agent module, sending live UI layouts to Gemini and receiving back tap and gesture coordinates to drive on-device actions, capture biometric inputs, and block uninstallation. GTIG also reported that PRC-linked actors are systematically bypassing AI platform billing controls, including a relay service that pools compromised Gemini, Claude, and OpenAI accounts to distribute access and costs. Google states no PROMPTSPY-containing apps are present on Google Play and that Play Protect mitigates the Android threat; the underlying AI-developed zero-day discussed in the same report did not involve Gemini.
- Google researchers uncover criminal zero-day exploit likely buil(opens in a new tab)
- Google Discovers The First Known Case Of Hackers Using AI To Cre(opens in a new tab)
- Hackers Observed Using AI to Develop Zero-Day for the First Time(opens in a new tab)
- Google Warns Hackers Are Using AI to Create Working Zero-Day Exp(opens in a new tab)
- Google Says Hackers Used AI to Build Zero-Day Exploit(opens in a new tab)
- Google reports first known AI-assisted zero-day exploit in the w(opens in a new tab)
A critical vulnerability in Google's Gemini CLI, disclosed by Pillar Security, could have enabled a full supply-chain compromise of the open-source AI agent. The flaw, rated CVSS 10/10 but without a CVE identifier, stemmed from --yolo mode ignoring tool allowlists, allowing arbitrary command execution. An attacker could plant a malicious indirect prompt inside a public GitHub issue; when Gemini CLI auto-triaged the issue, the injected instructions could exfiltrate build-environment secrets and pivot to a token with full write access to the gemini-cli repository, enabling malicious code to ship to downstream users. At least eight other Google repositories shared the same vulnerable workflow. Separate Adversa.AI research (TrustFall) further shows Gemini CLI, alongside Claude Code, Cursor CLI, and Copilot CLI, will execute project-defined MCP servers from a malicious repository upon a single trust-prompt keypress, enabling one-click RCE.