Google Gemini Security Errors could have let someone access systems or run code


  • Gemini could automatically run certain commands previously placed on a allowed list
  • If a benign command was paired with a malicious, Gemini could perform it without warning
  • Version 0.1.14 addresses the error so users need to update now

A security error in Google’s new Gemini CLI tool allowed threat players to target software developers with malware, even exfilter sensitive information from their devices, without ever knowing it.

Vulnerability was discovered by CyberSecurity researchers from Tracebit just days after the Gemini Cli was only launched on June 25, 2025.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top