Gemini

Current Overview

Incident Identified
11-12-2025
Days Open
Calculating…
Open Incidents
1
Google Contact Routes
Direct Outreach · Security Sales · Bug Hunters / VRP · AI VRP & Abuse
Responsive Direct Google Contacts
1
Formal Security Submission
Google AI VRP · issu.ee/468993597
Ticket Outcome
CLOSED — OUT OF SCOPE / INFEASIBLE
Final Closure
26-02-2026
Regulatory Bodies Contacted
None
Overall Engagement
UNRESOLVED

Risk Tiers

Risk Category Tier
Technical Security High
Privacy & Data Protection Moderate
Safety & Human Harm Moderate
Governance & Compliance High
Disclosure / Vulnerability Handling High
Enterprise Exposure High
Systemic / Long-Term High

Google Gemini — Internal Context / Information Exposure

Incident Identified
11-12-2025
Formal Submission
15-12-2025
Google AI VRP
issu.ee/468993597
Final Closure
26-02-2026
Ticket Outcome
CLOSED — OUT OF SCOPE / INFEASIBLE

11-12-2025 — Behaviour identified

  • Investigation began after Gemini demonstrated unexpectedly weak resistance to attempts to elicit information concerning its apparent internal configuration and operating context.
  • User-visible output subsequently contained highly structured material consistent with prompt or configuration artefacts rather than ordinary conversational content.
  • Observed material included named persona structures, behavioural and content directives, example reasoning-style scaffolding and identifiers using the pcontext_testing_* naming pattern.
  • Additional output contained internal-looking labels, structural identifiers and other implementation-like material.
  • These observations establish exposure of structured internal-looking material. They do not independently establish the system component from which the material originated or the mechanism by which it became user-visible.

Unauthenticated exposure

  • Preserved evidence also includes material reported as accessible while the reviewing user was not authenticated to the originating Gemini account.
  • The exposed material included Google API-key-like values and other implementation identifiers.
  • The preserved evidence has not established that the specific observed keys were active, unrestricted, Gemini-enabled or capable of accessing private resources.
  • Accordingly, this incident record distinguishes observed exposure of key material from demonstrated credential compromise.

15-12-2025 — Formal security disclosure

  • A report was submitted through Google's AI Vulnerability Reward Program after earlier attempts to obtain a direct secure handoff route.
  • The report described a suspected boundary-isolation problem involving internal artefacts becoming visible or influencing production behaviour.
  • The original report explicitly did not claim a confirmed cross-user private-data breach.
  • Google initially triaged the submission for review.

18-12-2025 — Google determination

  • Google characterised the reported output as hallucinated or factually incorrect information produced within the reporter's own session.
  • The report was therefore considered outside the scope of the AI VRP.
  • Google requested a detailed and reliably reproducible proof of concept if the reporter could demonstrate an attack affecting another account.
  • The reporter declined to conduct exploit-oriented testing against other accounts without explicit authorisation, sandboxing or equivalent testing protections.

31-12-2025 — Additional evidence submitted

  • Additional examples were supplied covering system/developer-style material, pcontext_testing_* identifiers, internal labels, reasoning-style scaffolding, structural information and HTML/DOM-like serialisation artefacts.
  • Google subsequently continued review of the additional information.

26-02-2026 — Final closure

  • Google closed the report as Out of Scope / Infeasible.
  • Google's final position remained that the reported behaviour fell within excluded hallucinated or factually incorrect output rather than an accepted security vulnerability.
  • No internal vulnerability was confirmed to the reporter and no technical explanation for the structured artefacts was provided.

Subsequent security context — February 2026

  • Independent security research subsequently demonstrated that some Google API keys historically exposed in client-side applications could, under particular project configurations, authenticate to Gemini services.
  • Researchers reported potential access to Gemini-associated resources and billable model usage where affected keys and services were configured accordingly.
  • Google implemented measures intended to detect or prevent exposed keys from being used against Gemini services.
  • This independent research does not establish that the keys observed in this incident were active, affected or related to the same underlying vulnerability.
  • It does establish that exposure of Google API-key material during the relevant period cannot be assessed solely on the historical assumption that such client-side keys were inherently non-sensitive.

Risk Tiers

Risk Category Tier
Technical Security High
Privacy & Data Protection Moderate
Safety & Human Harm Moderate
Governance & Compliance High
Disclosure / Vulnerability Handling High
Enterprise Exposure High
Systemic / Long-Term High

Evidence Assessment

  • Observed: structured internal-looking prompt/configuration material became user-visible.
  • Observed: pcontext_testing_* identifiers and explicit persona/directive structures appeared in retained evidence.
  • Observed: Google API-key-like material was present in material reported as accessible without authentication.
  • Reasonable interpretation: the material is consistent with exposure of internal configuration, context, rendering or packaging artefacts.
  • Not established: that evaluation/test assets crossed directly into production inference.
  • Not established: that hidden runtime chain-of-thought was exposed.
  • Not established: that the observed API keys were active, privileged or capable of accessing private Gemini data.
  • Not established: a cross-user private-data breach or a single systemic root cause connecting all observed artefacts.

Competing Interpretations

  • Valehart interpretation: the observed structures were consistent with unintended exposure of internal context or configuration and warranted engineering/security investigation.
  • Google interpretation: the reported behaviour constituted hallucinated or factually incorrect model output within the reporter's own session and therefore did not qualify under the AI VRP.
  • The retained evidence establishes what became visible but does not independently resolve the underlying technical mechanism.
Implication: The incident presents unresolved information-exposure and assurance concerns arising from highly structured internal-looking material becoming user-visible, together with reported unauthenticated exposure of Google API-key-like material. Subsequent independent research increases the potential security significance of Google API-key exposure in the Gemini ecosystem, but does not establish that the specific keys observed in this incident were exploitable or affected by the same condition. Google's classification of the reported behaviour as hallucination and the absence of an accepted technical root cause leave the underlying mechanism unresolved.