“However, the build pipeline for compiling the sandbox binary included an automated step that adds security proto files to a binary whenever it detects that the binary might need them to enforce internal rules.”

Researchers pulled a 579 MB binary out of Gemini’s sandbox by printing it to the console in chunks. Inside were Google’s internal security proto files. Google’s security team had already reviewed the sandbox. Its own build pipeline put the files back in.