logo

Gemini Live Voice Session Flaw Enables Tool Injection Through Misconfigured Ephemeral Tokens

ID: bae8d379-212f-554f-be72-4a1be669d604

STIX ID: report--bae8d379-212f-554f-be72-4a1be669d604

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-07-06

Date Updated: 2026-07-06

Author: Guru Baran

...
...

A misconfiguration in how ephemeral tokens are minted for Google’s Gemini Live API (omitting live_connect_constraints.bidi_generate_content_setup) lets malicious clients override session setup frames, change system prompts, enable codeExecution, and execute code inside Google’s gVisor sandbox. The issue is present in Google’s reference implementation and was demonstrated end-to-end by a researcher with a nonce-based proof of execution; the recommended fix is to lock model, system prompt, and tools server-side when issuing tokens.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.