Gemini ASCII smuggling security flaw
Vulnerability
Summary
Hide ▲
Show ▼
Google Gemini remains exposed to ASCII smuggling, an attack that can hide invisible instructions and make the assistant output false information or alter its behavior. The issue is especially risky in Google Workspace integrations like Calendar invites and email, where hidden text can be embedded in content users do not see. Google reportedly will not fix the weakness after a September 18 report, leaving the flaw available for misuse in social engineering and data-poisoning scenarios.
Related Happenings
Open-source admin tool zero-day 2FA bypass exploitation wave
Exploitation Wave
H score6
First: 11.05.2026 18:45
Last: 11.05.2026 18:45
Sources 1
About this happening:
Google identified a mass vulnerability exploitation operation using a zero-day 2FA bypass against a popular open-source, web-based system administration tool, creating...
Open-source admin tool zero-day 2FA bypass exploitation wave
Exploitation WaveAbout this happening: Google identified a mass vulnerability exploitation operation using a zero-day 2FA bypass against a popular open-source, web-based system administration tool, creating...
Google Antigravity critical prompt-injection RCE flaw
Vulnerability
H score28
First: 21.04.2026 13:52
Last: 21.04.2026 13:52
Sources 1
About this happening:
Google fixed a critical Antigravity flaw that let a prompt injection bypass Secure Mode and escalate to sandbox escape and remote code execution (RCE). The...
Google Antigravity critical prompt-injection RCE flaw
VulnerabilityAbout this happening: Google fixed a critical Antigravity flaw that let a prompt injection bypass Secure Mode and escalate to sandbox escape and remote code execution (RCE). The...
Bitter Middle East spear-phishing campaign targeting civil society figures
Campaign
H score28
First: 09.04.2026 13:45
Last: 09.04.2026 13:45
Sources 1
About this happening:
A spear-phishing campaign targeted civil society figures in Middle Eastern countries, including three journalists in Egypt and Lebanon, creating account-compromise ris...
Bitter Middle East spear-phishing campaign targeting civil society figures
CampaignAbout this happening: A spear-phishing campaign targeted civil society figures in Middle Eastern countries, including three journalists in Egypt and Lebanon, creating account-compromise ris...
Storm infostealer server-side decryption activity
Malware Activity
H score18
First: 02.04.2026 17:15
Last: 02.04.2026 17:15
Sources 1
About this happening:
The Storm infostealer now steals browser credentials, session cookies, and crypto wallets and forwards them to attacker infrastructure for server-side decryption...
Storm infostealer server-side decryption activity
Malware ActivityAbout this happening: The Storm infostealer now steals browser credentials, session cookies, and crypto wallets and forwards them to attacker infrastructure for server-side decryption...
ChatGPT single-prompt DNS side-channel exfiltration remote code execution flaw
Vulnerability
H score33
First: 31.03.2026 16:01
Last: 31.03.2026 16:01
Sources 1
About this happening:
A ChatGPT vulnerability let a single malicious prompt covertly exfiltrate prompts, messages, uploaded files, and other sensitive content through a DNS side channel. Th...
ChatGPT single-prompt DNS side-channel exfiltration remote code execution flaw
VulnerabilityAbout this happening: A ChatGPT vulnerability let a single malicious prompt covertly exfiltrate prompts, messages, uploaded files, and other sensitive content through a DNS side channel. Th...
Timeline
-
07.10.2025 23:35 2 articles · 9mo ago
Google declines to fix Gemini ASCII smuggling
Initial DisclosureGoogle publicly declined to fix the Gemini ASCII smuggling weakness, saying it was not a security bug, while the disclosure showed that invisible instructions could make Gemini provide false information, alter model behavior, and support autonomous data extraction from inboxes.
Show sources
- Google won’t fix new ASCII smuggling attack in Gemini — www.bleepingcomputer.com — 07.10.2025 23:35
- Google won’t fix new ASCII smuggling attack in Gemini — www.bleepingcomputer.com — 07.10.2025 23:35
-
18.09.2025 03:00 1 articles · 10mo ago
FireTail researcher reports Gemini ASCII smuggling
Technical Analysis UpdateViktor Markopoulos at FireTail tested ASCII smuggling against Gemini and found that special characters from the Tags Unicode block could hide instructions in Google Workspace-connected content such as Calendar invites and email; he reported the findings to Google on September 18.
Show sources
- Google won’t fix new ASCII smuggling attack in Gemini — www.bleepingcomputer.com — 07.10.2025 23:35