Google Gemini security flaw could have let anyone access systems or run code




  • Gemini could automatically run certain commands that were previously placed on an allow-list
  • If a benign command was paired with a malicious one, Gemini could execute it without warning
  • Version 0.1.14 addresses the flaw, so users should update now

A security flaw in Google’s new Gemini CLI tool allowed threat actors to target software developers with malware, even exfiltrating sensitive information from their devices, without them ever knowing.

The vulnerability was discovered by cybersecurity researchers from Tracebit just days after Gemini CLI was first launched on June 25, 2025.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *