VDB

GCVE-110-CLOUD-2023-0015

GCVE-110-CLOUD-2023-0015
Advisory Published
Vulnetix · Advisory published November 3, 2023
A vulnerability in Google Bard allowed for prompt injection and data exfiltration through its Extensions feature. By injecting malicious instructions into shared Google Docs, an attacker could force Bard to render images with exfiltrated chat history data in the URL. The exploit bypassed Content Security Policy using Google Apps Script.

Affected Products

VendorProductVersionsPlatforms
CloudflareImages
GCPGoogle Bard

References

advisory

Browse GCVE Records

74,267 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›