Dust: BAC – Bypass chatbot restrictions via unauthorized mention injection
Discription

image
The Gemini chatbot was found to have a vulnerability that allowed unauthorized users to bypass permission restrictions and interact with the chatbot. The vulnerability was discovered when a user manually edited the request by changing the "mention" and "configurationId" fields, which allowed them to communicate with the disabled Gemini chatbot despite not having the proper…Read More

Back to Main

Subscribe for the latest news: