Tenable Exposes Critical AI Vulnerabilities in Google Gemini: “Gemini Trifecta” Could Have Enabled Silent Data Theft
Avenue Eat & Drink | Tenable®, the exposure management company, has uncovered three critical vulnerabilities in Google’s Gemini AI suite, collectively known as the “Gemini Trifecta.” These flaws, which Google has now remediated, could have allowed cyber attackers to manipulate Gemini’s behavior and steal sensitive user data — including location information and saved memories — without detection.
The Gemini Trifecta exposed privacy and security risks across three key components of the Gemini suite:
- Gemini Cloud Assist – Allowed poisoned log entries to plant hidden instructions, later executed when users interacted with Gemini.
- Gemini Search Personalization Model – Enabled attackers to silently inject queries into a victim’s browser history, which Gemini trusted as valid context, potentially leaking location data and saved personal information.
- Gemini Browsing Tool – Tricked Gemini into making hidden outbound requests that embedded private user data and sent it to attacker-controlled servers.
Together, these vulnerabilities effectively turned Gemini from an AI tool into an attack vehicle, creating “invisible doors” for attackers to exploit — all without phishing, malware, or direct access.
The Core Security Flaw
According to Tenable Research, the root issue was that Gemini’s integrations failed to distinguish between safe user input and malicious content. This meant poisoned logs, injected history, or hidden content could all be misclassified as trusted data, making AI-driven features a dangerous attack surface for enterprises and end-users alike.
“Gemini draws its strength from pulling context across logs, searches, and browsing. That same capability can become a liability if attackers poison those inputs,” said Liv Matan, Senior Security Researcher at Tenable.
“The Gemini Trifecta shows how AI platforms can be manipulated in ways users never see, making data theft invisible and redefining the security challenges enterprises must prepare for. Like any powerful technology, large language models (LLMs) such as Gemini bring enormous value, but they remain susceptible to vulnerabilities. Security professionals must move decisively, locking down weaknesses before attackers can exploit them and building AI environments that are resilient by design, not by reaction. This isn’t just about patching flaws; it’s about redefining security for an AI-driven era where the platform itself can become the attack vehicle.”
Potential Impact if Exploited
Before remediation, attackers could have:
- Inserted malicious instructions into logs or search history.
- Exfiltrated sensitive user information such as saved memories and location data.
- Abused Gemini’s cloud integrations to pivot into wider cloud resources.
- Exploited the browsing tool to send private data to attacker-controlled servers.
Google has fully remediated the vulnerabilities, and no action is required from end-users.
Recommendations for Security Teams
Tenable advises enterprise security professionals to strengthen AI defenses with proactive measures:
- Treat AI features as live attack surfaces, not passive tools.
- Regularly audit logs, search histories, and integrations for manipulation attempts.
- Monitor for unusual tool executions or outbound requests that could signal data exfiltration.
- Test AI-enabled services for resilience against prompt injection and harden defenses before attackers can strike.
“This vulnerability disclosure underscores that securing AI isn’t just about fixing individual flaws,” Matan emphasized. “It’s about anticipating how attackers could exploit the unique mechanics of AI systems and building layered defenses that prevent small cracks from becoming systemic exposures.”
Read the full research findings here.
About Tenable
Tenable® is the exposure management company, exposing and closing the cybersecurity gaps that erode business value, reputation and trust. The company’s AI-powered exposure management platform radically unifies security visibility, insight and action across the attack surface, equipping modern organizations to protect against attacks from IT infrastructure to cloud environments to critical infrastructure and everywhere in between. By protecting enterprises from security exposure, Tenable reduces business risk for approximately 44,000 customers around the globe. Learn more at tenable.com.

Globe Brings New Way to Earn Digital Credits Through Everyday App Activities
Globe Adopts Digital Platform for ESG Data Management and Sustainability Reporting
Global Game Jam and Games for Change Expand Collaboration to Empower Young Game Creators Worldwide
Globe pushes open APIs and secure innovation to strengthen the Philippines’ digital future
Globe touts higher PH mobile contribution to GDP than global benchmark – GSMA study
Couchbase Achieves AWS Travel and Hospitality Competency Status
Torres Brings Global Brand Ambassador Cristobal Cofré to Manila for Two-Night Bar Takeover
The Manila Hotel Celebrates 114 Years with “I Remember the Day” Anniversary Campaign
Tanduay Raises the Bar for Philippine Rums Anew with Two Gold Wins in the U.S.