Read SafeBreach's new Gemini paper last night. The technique itself is clever. A question in Chinese hidden behind an English one, so the user says yes to the English question while Gemini's backend security check thinks the yes maps to the Chinese one. Or the same idea using a clickable link whose URL the TTS engine refuses to read aloud. Either way, the model gets fooled, the tool fires.

But that's normal. Cat-and-mouse between security researchers and model vendors has been going for two years now. Bypass gets found. Vendor patches. New bypass gets found. Vendor patches. Forever.

What stuck with me was the timeline at the bottom.

SafeBreach reported the vulnerability to Google on August 17, 2025. Google patched it on November 14, 2025. That's three months. Three months in which any attacker could hijack Gemini's voice assistant via any notification app, WhatsApp, Slack, SMS, Signal, to do tool execution on the victim's phone. Open smart home devices. Stream video via Zoom without consent. Fake messages from people in the victim's contacts. Even poison Gemini's long-term memory, which is tied to the Google Workspace account, so the poison propagates to the tablet and the laptop too.