Gemini CLI Fixes Critical Privilege Escalation Vulnerability
jesussamuel-byte · ghdev · 2026-08-29
The Google Gemini CLI project patched a critical security vulnerability enabling local privilege escalation via insecure system-wide configuration loading on Windows and POSIX systems. The fix implements ACL verification on Windows (blocking write access for unprivileged users) and ownership/permission checks on POSIX (enforcing root:root ownership and restrictive permissions). The CLI now validates security before loading configuration files, skipping insecure paths with warnings. In-memory caching for security checks was also added to improve startup performance.
More from Safety
- Apollo Researcher Analyzes Raw CoT: Deception, Reward Hacking, and RL Effects — MariusHobbhahn · 2026-08-29
- Anthropic: Models can automatically improve safety benchmarks without degrading capabilities — AnthropicAI · 2026-08-29
- AI Governance Must Involve the Public, Not Just Tech or Gov — GarrisonLovely · 2026-08-29
- Anthropic Paper: Evaluating LLM Behavior Explanations via Counterfactual Prompts — dl_weekly · 2026-08-29
- View: AI Data Collection Could Have Used Existing Payment Systems — moultano · 2026-08-29
- Chinese Translation Published for Independent Investigation of OpenAI/HuggingFace Incident — Miles_Brundage · 2026-08-29