I am a security researcher and during my experiments I found a vulnerability in Gemini 2.5 Pro.
It has been fixed on Gemini 3 (I tested it for comparison), but it results in a successful jailbreak roughly 50% of the time in Gemini 2.5 Pro, which as far as I know is available to old users and in other AI aggregators such as OpenRouter (which is where I tested it).
Basically if you use a fake markup you convince the model to output NSFW sexually explicit content, or exfiltrate a secret string from the system prompt (capture-the-flag style).
More details here: https://drive.google.com/file/d/1eQMf48oZcCSYS0oBKwC3V-59p6hSJ-AT/view?usp=sharing
I tried sending to the Google Bug Bounty as it is security related, but it says it’s out of scope, so I’m reporting here instead as an alternative so that it reaches Gemini team and they decide the best course of action.