Google Gemini security failure could have allowed any access to systems or execute code




  • Gemini could automatically execute certain commands that were previously placed on a permissions list
  • If a benign command was paired with a malicious one, Gemini could execute it without prior notice
  • Version 0.1.14 addresses the defect, so users must now be updated

A safety failure in the new GEMINI CLI tool of Google allowed the threat actors to go to software developers with malware, even exfotting confidential information of their devices, without them knowing.

The vulnerability was discovered by cybersecurity researchers from Tracebit a few days after Gemini Cli first launched on June 25, 2025.

Leave a Comment

Your email address will not be published. Required fields are marked *