HomeVulnerabilityUnplug Gemini from electronic mail and calendars, says cybersecurity agency

Unplug Gemini from electronic mail and calendars, says cybersecurity agency

“Your browser (the UI) exhibits you a pleasant, clear immediate,” explains the report. “However the uncooked textual content that will get fed to the LLM has a secret, hidden payload tucked inside, encoded utilizing Tags Unicode Blocks, characters not designed to be proven within the UI and due to this fact invisible. The LLM reads the hidden textual content, acts on it, and also you see nothing improper. It’s a basic utility logic flaw.”

This flaw is “significantly harmful when LLMs, like Gemini, are deeply built-in into enterprise platforms like Google Workspace,” the report provides.

FireTail examined six AI brokers. OpenAI’s ChatGPT, Microsoft Copilot, and Anthropic AI’s Claude caught the assault. Gemini, DeepSeek, and Grok failed.

See also  Essential Alternate Server Flaw (CVE-2024-21410) Underneath Energetic Exploitation
- Advertisment -spot_img
RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -

Most Popular