Cybersecurity researchers have disclosed three now-patched security vulnerabilities impacting Google's Gemini artificial intelligence (AI) assistant that, if successfully exploited, could have exposed users to major privacy risks and data theft. "This should be possible since Gemini has the permission to query assets through the Cloud Asset API." Thus, when the victim later interacts with Gemini's search personalization model, the attacker's instructions are processed to steal sensitive data. "The Gemini Trifecta shows that AI itself can be turned into the attack vehicle, not just the target. "Protecting AI tools requires visibility into where they exist across the environment and strict enforcement of policies to maintain control."