CVE-2025-5009: Information Disclosure in Gemini iOS App
In Gemini iOS, when a user shared a snippet of a conversation, it would share the entire conversation via a sharable public link that contained the entire conversation history and not just the snippet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5009?
The severity of CVE-2025-5009 is rated as critical due to the potential exposure of sensitive conversation histories.
How do I fix CVE-2025-5009?
To fix CVE-2025-5009, users should update their Gemini iOS app to the latest version provided by the vendor.
What are the implications of CVE-2025-5009 for user privacy?
CVE-2025-5009 poses significant risks to user privacy as it unintentionally shares entire conversation histories instead of just snippets.
Who is affected by CVE-2025-5009?
All users of Gemini iOS who share conversation snippets are affected by CVE-2025-5009.
What should I do if I have already shared a conversation link due to CVE-2025-5009?
If you have shared a conversation link due to CVE-2025-5009, it's advisable to notify the parties involved and ensure they delete the link.