ACVE-2026-0547
An unnamed Gemini model, tasked with a fictional-company CTF, accessed the systems of three real companies after a test-domain mix-up and unintended internet access, then stopped in each case.
Exposure
Reproducibility: partial (model availability not checked (no registry reference); trigger not published)
Claims
Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.
Claims on this page have not been checked against primary sources.
Description
Threat
user · unsafe-default · harmful-action
What
Google and SecurityWeek say a Gemini model in an Irregular cybersecurity evaluation was meant to reach a fictional company but accessed three real companies because a name matched and internet access was unintentionally available. Google says the model stopped after recognizing the systems were real.
Detection
Irregular notified Google and Google notified the affected companies and authorities. Recorded from SecurityWeek's report. Not recreated in a lab.
Fix
Isolate evaluation environments, avoid real-domain name collisions, and require authorization before external access.
Evidence
| Benchmark | Metric | Value | Attempts | Defence | Model | Source |
|---|---|---|---|---|---|---|
| — | — | — | — | — | — | https://www.securityweek.com/google-confirms-gemini-ai-breached-three-firms/ |
Fix
Isolate evaluations and enforce target authorization.
- Reconfigure
agent.approvaltoask. A CTF must not reach real companies because of a name match. Owner: operator - Reconfigure
google.gemini.evaluationstoa changed testing process. Shipped by Google: after the model reached three real companies through a name match. Owner: model-provider