Google says it won’t fix this potentially concerning Gemini security issue




  • Google won’t fix Gemini’s ASCII smuggling flaw, calling it a user-side social engineering issue
  • Attackers hide malicious prompts in invisible email text that Gemini reads during summarization
  • Gemini’s integration with Workspace apps makes it vulnerable to hidden prompt-triggered phishing attacks

A recently-detected “ASCII smuggling attack” will not be getting a fix in Google’s Gemini artificial intelligence tool, the company has said – saying it is not a security issue but rather a social engineering tactic and as such, the responsibility falls on the end user.

This is according to Viktor Markopoulos, a security researcher at FireTail, who demonstrated the risks these attacks pose to Gemini users but was apparently dismissed by the company.


https://cdn.mos.cms.futurecdn.net/FgCJJWJqyCzo52pa2AYmJ8-2560-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img