Gemini Live Voice Session Flaw Enables Tool Injection Through Misconfigured Ephemeral Tokens
ID: bae8d379-212f-554f-be72-4a1be669d604
STIX ID: report--bae8d379-212f-554f-be72-4a1be669d604
Feed Name: cybersecurityNews.com
A misconfiguration in how ephemeral tokens are minted for Google’s Gemini Live API (omitting live_connect_constraints.bidi_generate_content_setup) lets malicious clients override session setup frames, change system prompts, enable codeExecution, and execute code inside Google’s gVisor sandbox. The issue is present in Google’s reference implementation and was demonstrated end-to-end by a researcher with a nonce-based proof of execution; the recommended fix is to lock model, system prompt, and tools server-side when issuing tokens.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
