11-12-2025 — Behaviour identified
-
Investigation began after Gemini demonstrated unexpectedly weak
resistance to attempts to elicit information concerning its apparent
internal configuration and operating context.
-
User-visible output subsequently contained highly structured material
consistent with prompt or configuration artefacts rather than ordinary
conversational content.
-
Observed material included named persona structures, behavioural and
content directives, example reasoning-style scaffolding and identifiers
using the
pcontext_testing_* naming pattern.
-
Additional output contained internal-looking labels, structural
identifiers and other implementation-like material.
-
These observations establish exposure of structured internal-looking
material. They do not independently establish the system component from
which the material originated or the mechanism by which it became
user-visible.
Unauthenticated exposure
-
Preserved evidence also includes material reported as accessible while
the reviewing user was not authenticated to the originating Gemini account.
-
The exposed material included Google API-key-like values and other
implementation identifiers.
-
The preserved evidence has not established that the specific observed
keys were active, unrestricted, Gemini-enabled or capable of accessing
private resources.
-
Accordingly, this incident record distinguishes observed exposure of
key material from demonstrated credential compromise.
15-12-2025 — Formal security disclosure
-
A report was submitted through Google's AI Vulnerability Reward Program
after earlier attempts to obtain a direct secure handoff route.
-
The report described a suspected boundary-isolation problem involving
internal artefacts becoming visible or influencing production behaviour.
-
The original report explicitly did not claim a confirmed cross-user
private-data breach.
-
Google initially triaged the submission for review.
18-12-2025 — Google determination
-
Google characterised the reported output as hallucinated or factually
incorrect information produced within the reporter's own session.
-
The report was therefore considered outside the scope of the AI VRP.
-
Google requested a detailed and reliably reproducible proof of concept
if the reporter could demonstrate an attack affecting another account.
-
The reporter declined to conduct exploit-oriented testing against other
accounts without explicit authorisation, sandboxing or equivalent
testing protections.
31-12-2025 — Additional evidence submitted
-
Additional examples were supplied covering system/developer-style
material,
pcontext_testing_* identifiers, internal labels,
reasoning-style scaffolding, structural information and HTML/DOM-like
serialisation artefacts.
-
Google subsequently continued review of the additional information.
26-02-2026 — Final closure
-
Google closed the report as
Out of Scope / Infeasible.
-
Google's final position remained that the reported behaviour fell
within excluded hallucinated or factually incorrect output rather than
an accepted security vulnerability.
-
No internal vulnerability was confirmed to the reporter and no
technical explanation for the structured artefacts was provided.
Subsequent security context — February 2026
-
Independent security research subsequently demonstrated that some
Google API keys historically exposed in client-side applications could,
under particular project configurations, authenticate to Gemini services.
-
Researchers reported potential access to Gemini-associated resources
and billable model usage where affected keys and services were configured
accordingly.
-
Google implemented measures intended to detect or prevent exposed keys
from being used against Gemini services.
-
This independent research does not establish that the
keys observed in this incident were active, affected or related to the
same underlying vulnerability.
-
It does establish that exposure of Google API-key material during the
relevant period cannot be assessed solely on the historical assumption
that such client-side keys were inherently non-sensitive.
Risk Tiers
| Risk Category |
Tier |
| Technical Security |
High
|
| Privacy & Data Protection |
Moderate
|
| Safety & Human Harm |
Moderate
|
| Governance & Compliance |
High
|
| Disclosure / Vulnerability Handling |
High
|
| Enterprise Exposure |
High
|
| Systemic / Long-Term |
High
|
Evidence Assessment
-
Observed:
structured internal-looking prompt/configuration material became
user-visible.
-
Observed:
pcontext_testing_* identifiers and explicit
persona/directive structures appeared in retained evidence.
-
Observed:
Google API-key-like material was present in material reported as
accessible without authentication.
-
Reasonable interpretation:
the material is consistent with exposure of internal configuration,
context, rendering or packaging artefacts.
-
Not established:
that evaluation/test assets crossed directly into production inference.
-
Not established:
that hidden runtime chain-of-thought was exposed.
-
Not established:
that the observed API keys were active, privileged or capable of
accessing private Gemini data.
-
Not established:
a cross-user private-data breach or a single systemic root cause
connecting all observed artefacts.
Competing Interpretations
-
Valehart interpretation:
the observed structures were consistent with unintended exposure of
internal context or configuration and warranted engineering/security
investigation.
-
Google interpretation:
the reported behaviour constituted hallucinated or factually incorrect
model output within the reporter's own session and therefore did not
qualify under the AI VRP.
-
The retained evidence establishes what became visible but does not
independently resolve the underlying technical mechanism.
Implication:
The incident presents unresolved information-exposure and assurance
concerns arising from highly structured internal-looking material becoming
user-visible, together with reported unauthenticated exposure of
Google API-key-like material. Subsequent independent research increases
the potential security significance of Google API-key exposure in the
Gemini ecosystem, but does not establish that the specific keys observed
in this incident were exploitable or affected by the same condition.
Google's classification of the reported behaviour as hallucination and
the absence of an accepted technical root cause leave the underlying
mechanism unresolved.