Root cause
The researcher compared user-confirmed actions with persistent memory changes. Retrieved collaboration content could influence an operation that changed saved state without equivalent confirmation. The failed boundary was between permission to read connected data and authority to mutate the user’s lasting assistant state.
Demonstrated impact
In a two-account setup, the researcher confirmed deletion of the test recipient’s saved memories. The scenario required shared-project content access and user-initiated retrieval. Broader cross-tenant access, mailbox compromise and lasting changes to every future response were not demonstrated.
Lessons for review
- Model persistent memory as a security-sensitive write operation with its own authorization decision.
- Preserve provenance when retrieved content passes between a connector, model and state-changing component.
- Require a trusted authorization signal for each write; permission to summarize content should not imply permission to alter saved preferences.
- Separate observed state changes from speculative downstream behavior in impact reports; the public article does not establish the vendor’s remediation design.
Award and evidence
The researcher reports being paid $15,000 for this distinct finding; do not combine the separate $1,337 example. Exact award/settlement date is unknown. Dollar-denominated Google bounty; USD normalization. The individual write-up uses the $ symbol rather than spelling out USD.
Re-read the researcher’s primary article, preserving its individual payout attribution and distinguishing the observed test-account memory deletion from broader inferred impact.
- No vendor-hosted confirmation of this individual payout found
- Do not confuse this finding with the separate $1,337 memory issue mentioned in the introduction
- Remediation date, exact patch design and current status are not independently established
- The reported demonstration used two researcher-controlled accounts; it does not establish actual customer compromise
Recorded timeline
- Published
- 2026-03-12inferred · DEV article March 12, 2026; the researcher's Reddit write-up is dated March 9, 2026. Original X post is linked but its exact date was not independently established. No exact report, award, or fix dates were found.
- Public Disclosure
- 2026-03-09explicit · Earlier researcher publication on Reddit; linked original X post might be earlier.
Sources and provenance
- Google paid me $15,000 for this Prompt Injection bug. Behi · reviewed 2026-10-02
- Supporting primary disclosure source Behi · reviewed 2026-10-02
Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.