Three new vulnerabilities in Google's AI assistant, Gemini, could allow attackers to extract stored user information and location data.

The vulnerabilities discovered by Tenable, dubbed the “Gemini Trifecta,” show how AI systems can become “attack vehicles” rather than just targets. The research revealed significant privacy risks across multiple components of the Gemini ecosystem.
Although Google has already patched the issues, the discovery serves as a critical reminder of the security challenges inherent in AI platforms. The three distinct vulnerabilities targeted different functions within Gemini.
See also: Chinese hackers exploit VMware zero-day since October 2024
Gemini Trifecta: Three vulnerabilities in the AI assistant
- Gemini Cloud Assist: A command injection in Google Cloud could allow attackers to compromise cloud resources or perform phishing attempts. Researchers found that log entries, which Gemini can summarize, could be infected with malicious commands. This represents a new class of attack where log injections can manipulate AI inputs.
- Gemini Search Personalization Model: This search-injection flaw allowed attackers to control Gemini's behavior by manipulating a user's Chrome search history. By injecting malicious search queries, an attacker could trick Gemini into leaking a user's stored information and location data .
- Gemini Browsing Tool: A vulnerability in this tool allowed the direct extraction of a user's stored information . Attackers could exploit the tool's functionality to send sensitive data to an external server.

The basic attack methodology involved a two-step process: infiltration and extraction. Attackers first had to insert a malicious command that Gemini would process as a legitimate command.
Tenable discovered covert methods for this “indirect command injection,” such as embedding instructions in the User-Agent header of a log entry or using JavaScript to add malicious queries to a victim’s browsing history.
See also: CISA warns of vulnerability in Libraesva ESG
After entering the command, the next challenge was extracting the data, bypassing Google's security measures that filter out output such as hyperlinks and image tags.
The researchers discovered that they could exploit the Gemini Browsing Tool as a side channel. They created a command that instructed Gemini to use its browsing tool to retrieve a URL, embedding the private data directly into the URL request, which was sent to a server controlled by an attacker.
This extraction was performed via tool execution (instead of response rendering), bypassing many of Google's defenses.
Google has successfully patched all three vulnerabilities. The fixes include stopping hyperlink rendering in log summaries, restoring the vulnerable search personalization model, and preventing data extraction through the browser tool during indirect command inputs.

AI systems can be a risk
The three vulnerabilities in Gemini highlight a larger truth: modern AI assistant systems operate as complex assemblies of services, and each of their components can be turned into a channel for leakage or abuse. Beyond immediate technical remediation, organizations and designers must adopt a multi-layered security strategy that covers both the structure and behavior of AI agents. This means incorporating secure input and output patterns, limiting rendering capabilities, and continuously evaluating side-channels that emerge from navigation, summarization, and personalization tools.
See also: Hacker sells exploit for Veeam vulnerability on the dark web
On a practical level, security teams should build detection mechanisms that don't rely solely on signatures: anomaly detection in digest streams, rate-limiting for tasks that generate external requests, and checking for data transformations embedded in URLs or headers. In addition, the helper architecture should separate privileged operations from those that interact with untrusted sources — the principle of least privilege at every level.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Finally, the regulatory and ethical dimensions are not secondary: policies are needed for the handling of sensitive data by AI, clear accountability flows and informing users about how their personal information is protected. In addition, training programs for users and developers reduce the human factor in the risk chain and improve incident preparedness.
