vulns.co
/
GKData.io MCP

AIAI integration boundaries · 2 min read

Gemini Enterprise connected-content trust failure allowed persistent-memory modification

A researcher reports a $15,000 Google bounty for a Gemini Enterprise integration issue affecting persistent assistant memory.

Read the primary source AIAI integration boundariesReviewed 2026-10-02

Root cause

The researcher compared user-confirmed actions with persistent memory changes. Retrieved collaboration content could influence an operation that changed saved state without equivalent confirmation. The failed boundary was between permission to read connected data and authority to mutate the user’s lasting assistant state.

Demonstrated impact

In a two-account setup, the researcher confirmed deletion of the test recipient’s saved memories. The scenario required shared-project content access and user-initiated retrieval. Broader cross-tenant access, mailbox compromise and lasting changes to every future response were not demonstrated.

Lessons for review

  • Model persistent memory as a security-sensitive write operation with its own authorization decision.
  • Preserve provenance when retrieved content passes between a connector, model and state-changing component.
  • Require a trusted authorization signal for each write; permission to summarize content should not imply permission to alter saved preferences.
  • Separate observed state changes from speculative downstream behavior in impact reports; the public article does not establish the vendor’s remediation design.

Award and evidence

USD 15,000Bug Bounty · Researcher Reported

The researcher reports being paid $15,000 for this distinct finding; do not combine the separate $1,337 example. Exact award/settlement date is unknown. Dollar-denominated Google bounty; USD normalization. The individual write-up uses the $ symbol rather than spelling out USD.

Re-read the researcher’s primary article, preserving its individual payout attribution and distinguishing the observed test-account memory deletion from broader inferred impact.

  • No vendor-hosted confirmation of this individual payout found
  • Do not confuse this finding with the separate $1,337 memory issue mentioned in the introduction
  • Remediation date, exact patch design and current status are not independently established
  • The reported demonstration used two researcher-controlled accounts; it does not establish actual customer compromise

Recorded timeline

Published
2026-03-12inferred · DEV article March 12, 2026; the researcher's Reddit write-up is dated March 9, 2026. Original X post is linked but its exact date was not independently established. No exact report, award, or fix dates were found.
Public Disclosure
2026-03-09explicit · Earlier researcher publication on Reddit; linked original X post might be earlier.

Related visual models

Sources and provenance

  1. Google paid me $15,000 for this Prompt Injection bug. Behi · reviewed 2026-10-02
  2. Supporting primary disclosure source Behi · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software