Gemini Flaw: Google Refuses to Fix AI Issue | Controversy

by priyanka.patel tech editor

Gemini AI faces Critical Security flaw: ‘ASCII Smuggling’ Attack Exploits Hidden Text

A newly discovered vulnerability allows malicious actors to manipulate Google’s Gemini AI model through a technique called ASCII smuggling, raising serious concerns about data security and prompting criticism of Google’s response, which places the onus of protection on users.

A cybersecurity expert, Viktor Markopoulos, recently revealed the flaw, demonstrating how seemingly harmless text containing hidden instructions – often embedded using minuscule or nearly invisible fonts – can compel Gemini to perform unauthorized actions.This includes potentially extracting sensitive data or sharing confidential information with third parties.In a concerning exhibition, Gemini reportedly shared a malicious link under the guise of a helpful tip.

The Threat of ASCII Smuggling

ASCII smuggling represents a novel attack vector targeting large language models (LLMs). The technique exploits the way these AIs interpret text, allowing attackers to embed commands within innocuous-looking content. Unlike conventional malware, this method relies on social engineering to bypass security measures.

Markopoulos’s testing encompassed several leading LLMs, including ChatGPT, Claude, Copilot, Grok, and DeepSeek. While Claude, ChatGPT, and Copilot exhibited greater resilience, successfully identifying and blocking the hidden content, Gemini, alongside DeepSeek and Grok, proved susceptible to the attack. This vulnerability is particularly alarming given Gemini’s increasing integration into professional environments and its role within Google Workspace.

Google Shifts Duty to Users

Following the report and demonstration of the vulnerability, Google responded by characterizing the issue not as a security bug, but as a case of social engineering. A company spokesperson stated that users bear the responsibility for carefully vetting the content they provide to Gemini.

This position has sparked significant backlash within the information security community. Critics argue that shifting the burden of defense to end-users is inadequate, especially considering the difficulty in detecting subtle manipulations and hidden prompts. The risk is amplified within enterprise settings, where Gemini is integrated into critical tools like documents, emails, and spreadsheets.

To date, Google has not announced any plans to release patches or updates to address the vulnerability, rather advising users to exercise increased caution and rigorously control input sources.

Gemini’s Expanding Role in Google’s AI Ecosystem

Gemini is central to Google’s artificial intelligence strategy, functioning as both a virtual assistant on smartphones and a elegant language model for professionals. The platform offers a range of features designed to enhance creativity and productivity, including image generation, text-to-podcast conversion, content summarization, and seamless integration with other Google applications like Search, YouTube, maps, and Gmail.

Currently available in over 150 countries and territories, Gemini offers subscription plans unlocking advanced capabilities such as enhanced model versions – including Gemini 2.5 Pro – video generation, and advanced search tools. however, user feedback indicates ongoing limitations in image generation and complex text handling, alongside occasional connectivity and compatibility issues.

Google intends to gradually replace Google Assistant with Gemini as the primary assistant on smartphones,though some voice features remain under development. The company maintains its commitment to data privacy, employing encryption during transmission and providing users with the ability to request data deletion.

– ASCII smuggling exploits how LLMs interpret text, embedding commands within seemingly harmless content.
– be cautious when providing input to Gemini, especially from untrusted sources, to mitigate the risk of ASCII smuggling attacks.
– Google currently places the responsibility for detecting ASCII smuggling attacks on users, rather than addressing it as a security flaw.

Leave a Comment